Compliance & standards
How the ledger satisfies the regimes your auditors, risk and legal teams ask about. Full mappings live in the repository (SOVEREIGNTY.md, THREAT-MODEL.md, COMPLIANCE-STANDARDS.md); this is the in-app summary.
Australia. APP 1.7–1.9
Each record stores system, agent, version and payload (the inputs). The signature and received_at prove exactly when and by what version a decision was made. satisfying the automated-decision-making transparency obligations effective 10 December 2026.
EU. AI Act Art.12
The ledger is the automatic log for high-risk AI. AI-governance capture fields (risk, confidence, routing, human_verifier_id, reference_db_state) provide the model-logging and human-oversight evidence, and the ledger is exportable for technical documentation.
EU. GDPR
Storage limitation (Art.5(1)(e)) via per-org retention; right to erasure (Art.17) via signed cryptographic erasure that preserves the chain anchor.
United States
CCPA/CPRA §1798.105 right to delete via cryptographic erasure; Colorado AI Act and NYC Local Law 144 via the recorded record of the automated system and its logic inputs.
Posture: Minimum vs Gold Standard
- ✓Decisions recorded and signed with your Ed25519 key
- ✓Tamper-evident hash chain active
- ✓Key published at /.well-known/record-public-key
- ✓Retention & lawful-erasure policy set
- ✓Audit trail intact
The irreducible floor. A receipt is defensible in court or with a regulator.
- ✓Independent RFC 3161 trusted timestamping (TSA_URL)
- ✓External auditor on the roster (verifies offline)
- ✓Live, recent activity
- ✓AI-governance metadata captured (risk, confidence, human oversight)
Optional checks that raise posture toward Silver/Gold but are not required to be defensible.
Your live score is on the dashboard (Audit readiness). The Gold Standard view exposes what is present. and what is still missing. for an evidence-ready posture.