SOC 2 Type II
Controls mappedSecurity, availability, and confidentiality controls mapped to the Trust Services Criteria. Independent attestation comes later; we won’t imply a report exists before it does.
Audit-grade evidence. Vendor-neutral governance. Independent system of record.
We treat compliance as a deliverable, not a marketing claim. Below is the current state of each framework, with realistic timelines. Detailed mappings and audit reports are available under NDA in our security package.
An AI Bill of Materials (AI BOM) is a signed manifest of every component that makes up an agent: the model and version, the prompts, the tools and their permissions, the datasets, the libraries, the operator identity, and the policies in force at run time.
Without an AI BOM, you cannot answer the simplest audit questions: what model produced this decision, on which prompt, with what tool access, for which user? Every CPL agent ships with one. Every change is a new signed version.
Every agent run produces a signed evidence record: inputs, decision context, tool calls, approvals, model outputs, and the AI BOM in force at the time. Records are append-only, retained per policy, and exportable.
Standard tenancy is multi-tenant on Google Cloud with logical isolation, AES-256 at rest, TLS 1.3 in transit. Enterprise tier adds the controls below.
Public documents are linked directly. Documents marked under NDA are bundled in the security package and shared after a brief mutual NDA exchange.
The questions enterprise security teams ask us most often. If yours isn’t here, email [email protected].
Subprocessors process customer data on our behalf. The current list, effective dates, change feed, and API are maintained in the public subprocessor matrix.
Email our security team directly, or start a conversation through the contact form and we’ll route you to the right person.