Sectors

Compliance is not a horizontal layer.

Each regulated sector carries its own regime, its own evidentiary standard, and its own definition of an unacceptable failure. The sectors below are the ones the platform is built for — direction, not a client list.

01

Financial services

Model risk management, surveillance, and client-facing systems where every recommendation has to be explainable to a supervisor.

  • DORA
  • SR 11-7
  • MiFID II
  • SOC 2
Representative use cases
  • Credit memo drafting with full source attribution
  • Trade surveillance triage with reviewable rationale
  • Model risk documentation kept current automatically
02

Healthcare & life sciences

Clinical and research workloads where PHI never leaves the estate and provenance is a regulatory requirement, not a feature.

  • HIPAA
  • GxP
  • EU AI Act
  • ISO 13485
Representative use cases
  • Protocol and submission drafting against internal precedent
  • Prior-authorization evidence assembly
  • Safety signal triage across trial and literature corpora
03

Public sector & defense

Classified and controlled environments running fully disconnected, with deterministic behavior and complete audit reconstruction.

  • FedRAMP-aligned
  • CMMC
  • NIST 800-53
  • ITAR
Representative use cases
  • Air-gapped analyst assistance over controlled corpora
  • Field-deployed inference tolerant of comms loss
  • Records and FOIA response preparation
05

Energy & industrials

Plants, grids, and remote sites where connectivity is intermittent and the control environment is unforgiving.

  • NERC CIP
  • IEC 62443
  • ISO 45001
  • OSHA
Representative use cases
  • Local-first maintenance and procedure assistance
  • Incident reconstruction from operational history
  • Permit and compliance documentation generation
06

Insurance

Underwriting and claims systems subject to fairness testing, adverse-action explanation, and state-level scrutiny.

  • NAIC AI Model Bulletin
  • Solvency II
  • GDPR
  • SOC 2
Representative use cases
  • Submission intake and risk summarization
  • Claims triage with documented decision rationale
  • Bias testing across protected-class proxies
Compliance posture

What each regime actually requires of the system.

Not a badge wall. These are the obligations we design the architecture around, and what the running system produces to satisfy them.

EU AI Act

Risk classification & technical documentation

Use cases are classified by risk tier during scoping. High-risk deployments get the logging, human-oversight, and technical documentation the tier requires, generated by the running system.

ISO/IEC 42001

AI management system

We structure the engagement so your AI management system has real artifacts behind it — defined roles, impact assessments, and a change-control record for every model and policy version.

NIST AI RMF

Govern · Map · Measure · Manage

Our four-phase engagement maps directly onto the RMF functions, so the assessment output slots into an existing risk programme rather than sitting beside it.

SOC 2 Type II

Control evidence

Access enforcement, change management, and monitoring all emit evidence continuously. Control testing draws from the same audit log the system writes in normal operation.

HIPAA

PHI handling

PHI never leaves the covered entity's environment. Minimum-necessary access is enforced at retrieval, and every disclosure path is logged against an identified actor.

GDPR

Lawful basis & data subject rights

Lineage makes erasure and access requests tractable: because every generated span traces to source records, we can answer what was processed and remove it at source.

Operating under a regime not listed here? Tell us which one.

Assurance

Defensible under scrutiny, not just compliant on paper.

The difference between a system that passes review and one that survives an incident is whether it can explain itself afterwards.

Reconstructable decisions

Every output resolves to the retrieval set, policy version, model version, and actor identity that produced it.

Signed change control

Model, prompt, and policy changes are versioned artifacts with signed approval — no silent updates to a production system.

Human oversight paths

Escalation to a qualified reviewer is a runtime control with a recorded outcome, not a documented intention.

Independent evaluation

Evaluation sets are owned by your subject-matter experts. We do not grade our own homework.

Scope it against your regime.

Tell us the sector and the frameworks you answer to. We will come back with a risk-tiered view of which use cases are viable and what each one requires.