The Exogram Trust Center
Designed to support customer technical controls and audit evidence under EU AI Act Article 14 (Effective Human Oversight), SOC 2 Type II, HIPAA, and GDPR. Exogram provides deterministic enforcement and tamper-evident audit trails.
Compliance & Regulatory Alignment
Technical controls designed to substantiate enterprise audit evidence.
SOC 2 Type II
Audit Provenance & CC7
Provides pre-execution validation, cryptographic Merkle proofs, and tamper-evident audit trails to substantiate customer control effectiveness under CC6 and CC7 criteria.
EU AI Act & NIST
Article 14 Human Oversight
Supports EU AI Act Article 14 (Effective Human Oversight) and NIST AI RMF 1.0 via deterministic capability downgrading, rate limiting, and real-time human escalation switches.
HIPAA & GDPR
Privacy & Transparency
Zero data retention for foundation model training. Pre-evaluation PII scrubbing, tenant cryptographic isolation, and algorithmic rationale under GDPR Article 22.
Cryptographic Merkle Proofs vs. Storage Immutability
Enterprise auditors require clarity on how execution records are protected against tampering. Exogram distinguishes between mathematical verification and physical storage guarantees:
Cryptographic Merkle Proofs
Every evaluated action generates a SHA-256 HMAC state hash organized into Merkle tree roots. Any retroactive alteration to ledger records invalidates the mathematical hash chain, providing verifiable tamper-evidence that can be independently audited without trusting system operators.
Storage Immutability
Storage immutability (such as cloud WORM storage policies, object locking, and append-only database engines) prevents physical overwriting or deletion. Paired with Exogram's cryptographic Merkle proofs, enterprises achieve end-to-end audit defensibility.
Deployment Architectures & Isolation
Exogram evaluates metadata and schemas; customer enterprise data stays in customer VPC.
Multi-Tenant SaaS
Hosted Authority Runtime in SOC 2 audited AWS/Cloudflare environments. AES-256-GCM encryption, regional US & EU data residency, and sub-millisecond evaluation (0.07ms).
Dedicated VPC
Single-tenant deployment deployed inside dedicated customer cloud boundaries with AWS PrivateLink / VPC Peering, dedicated keys, and customer CMEK support.
Air-Gapped Sidecar
Self-hosted binary or Docker sidecar running directly within private Kubernetes clusters or sovereign air-gapped SCIFs with 100% local policy evaluation and zero external telemetry.
Data Flow Boundary Summary
Action intent, tool schemas, policy constraints, execution timestamps, capability tokens.
Raw prompt text, underlying database records, sensitive customer payloads, LLM context windows.
Data Isolation & Zero Training Guarantee
The Exogram Authority Runtime requires zero exposure to your underlying vector stores, LLM endpoints, or customer databases. Exogram processes evaluations in 0.07ms with AES-256-GCM encryption and zero data retention for AI model training.
Vendor Subprocessor Directory
Third-party infrastructure providers supporting Exogram services.