Compliance

Compliance is the substrate, not a feature.

The substrate that would earn every framework is already shipped. Formal certifications land as they clear audit — request the current status memo for any framework your procurement gate needs.

Frameworks

Frameworks Nebbos operates to.

  1. EU AI Act — Regulation (EU) 2024/1689

    Substrate implemented (Layer 07 memory + Layer 08 reasoning + Layer 15 attestation). Client-facing Annex IV documentation pack ships ahead of the 2027-08-02 Annex III deadline. Current status memo on request.

  2. SOC 2 Type II

    Trust services criteria (Security, Availability, Confidentiality, Privacy) implemented across the substrate. Audit engaged, observation window running. Report available under NDA as the auditor’s opinion issues.

  3. ISO 27001:2022

    Annex A control set implemented across identity, access, audit, encryption, and data retention. ISMS documentation and certification cycle scheduled. SoA + risk register + control narratives available under NDA on request.

  4. HIPAA (US healthcare clients)

    Technical safeguards implemented (access control, audit trail, integrity, entity authentication, transmission security). Administrative + physical safeguards + BAA template ship ahead of first healthcare deployment.

  5. FERPA (US K-12 + higher-ed clients)

    Substrate controls mapped to FERPA educational-records handling. Documented onboarding path for school districts and higher-ed.

  6. GDPR (EU clients + EU data subjects)

    Data Processing Addendum at /legal/dpa. Data-subject rights (access, correction, deletion, portability) implemented as first-class flows.

  7. CCPA + state privacy regimes

    Consumer rights implemented. State-by-state addenda where relevant.

Annex IV documentation pack, on the substrate that already generates it.

The EU AI Act treats certain deployments as high-risk (Article 6, Annex III) and requires providers to maintain a technical documentation pack covering architecture, data, monitoring, risk, and quality management (Article 11). Nebbos ships the substrate that generates that evidence today — Layer 07 memory captures the model artifacts, Layer 08 reasoning captures decision provenance, Layer 15 attestation captures the audit trail. The client-facing Annex IV pack lands ahead of the 2027-08-02 deadline. Request the current pack status memo via legal@nebbos.ai.

Trust services criteria, implemented at the substrate.

Security, Availability, Confidentiality, Privacy — every trust services criterion maps to a substrate control that already exists. The Type II audit is engaged and the observation window is running. Report available under NDA when the auditor’s opinion issues. Request the current control-implementation status memo via legal@nebbos.ai for procurement gates that need it before the report lands.

ISO 27001:2022

Annex A control set implemented across the substrate.

Every Annex A control that applies to a cloud-hosted platform — identity, access, audit, encryption, retention, incident response — is implemented today. The ISMS documentation and formal certification cycle are scheduled. Statement of applicability, risk register, and control narratives available under NDA on request via legal@nebbos.ai.

Which architecture layers make compliance real

Which architecture layers make compliance real.

  1. Layer 01 · Data

    Row-level isolation, encryption at rest, data-residency configurable per client.

  2. Layer 02 · Identity

    Human, service, workload identity classes with distinct authorization scopes. SSO + SCIM for enterprise.

  3. Layer 07 · Memory

    Retention policies configurable per client, per data class. GDPR erasure, HIPAA retention, FERPA educational-records handling.

  4. Layer 11 · Approval

    Human-in-the-loop is architectural. Article 14 of the EU AI Act (human oversight of high-risk systems) is satisfied by the approval graph.

  5. Layer 15 · Attestation

    Article 12 of the EU AI Act (record-keeping for high-risk systems) is satisfied by the append-only audit trail. Same trail satisfies SOC 2 CC7, ISO 27001 A.12.4, HIPAA 45 CFR 164.312(b).

Compliance-team questions

Compliance-team questions we field.

  1. Do you have a SOC 2 Type II report we can review?

    Not yet — SOC 2 Type II certification is in progress. Clients with SOC 2 as a vendor-review gate can request the current control-implementation status and the projected report date via legal@nebbos.ai.

  2. What is your data-residency posture?

    US + EU regions available. Additional regions available on the enterprise tier. Data residency configurable at client provisioning; data does not leave the elected region without client authorization.

  3. How do you handle GDPR data-subject rights requests?

    First-class client-admin flow. Client admin submits the request; Nebbos executes and returns evidence within the GDPR-mandated timeline.

  4. What is your policy on training on customer data?

    We do not train shared models on client data. Preference pairs your client produces stay in your client and are exportable to you. This is the training-substrate side of Nebbos.

  5. What sub-processors do you use?

    Full list on the security page. Sub-processor changes carry 30-day advance notice per DPA.

  6. What happens on data-breach notification obligations?

    We support client filing with a prepared evidence packet within regulatory timelines (GDPR 72 hours, HIPAA 60 days, state-specific).

Related

  • Trust — the meta-posture and accountability pillars

  • Security — technical controls in depth

  • Legal — MSA, DPA, Responsible Disclosure, Mutual NDA

  • Architecture — the 15 layers compliance rests on

Request an attestation or DPA.

Compliance · Substrate-first · SOC 2 · ISO 27001 · Annex IV · HIPAA · FERPA · GDPR — Nebbos