In stealth · work in progress
Trust centre

Compliance is foundation,
not feature.

tapestree is built to meet the privacy, security, payment, and AI-governance bar that enterprise customers and regulators require — and every tenant gets that floor, from a single user upward. It is not an enterprise upsell you unlock later. The heavier, sector-specific regimes below activate per deployment and per vertical; the baseline is the same for everyone.

P/01 · Privacy & data protection

Privacy by design, across regulatory regimes.

EU · UK

GDPR

Erasure cascades across all stores. Records of Processing Activities (ROPA) maintained. Breach workflow with ≤ 72h notification timer.

United States

CCPA / CPRA

Do-not-sell honoured. Global Privacy Control (GPC) signals respected. Consumer-rights workflow integrated.

India

DPDP Act 2023

Consent manager, multilingual notices, minor-data flags, cross-border transfer allowlists. Aligned to the regulatory floor of the founding region.

Canada

PIPEDA

Personal Information Protection and Electronic Documents Act compliance for Canadian deployments.

Brazil

LGPD

Lei Geral de Proteção de Dados — controller and processor obligations, data-subject rights, ANPD reporting.

Management system

ISO/IEC 27701

Privacy Information Management System (PIMS) layered on the ISMS — extends ISO 27001 controls with privacy-specific obligations.

P/02 · Security & governance

Defence in depth, governed at the management-system level.

ISMS

ISO/IEC 27001:2022

Information Security Management System designed to the ISO 27001 control set — with the cloud extensions 27017 (cloud-specific controls) and 27018 (PII in public clouds). Annex A.5.18 (access rights) enforced via OPA policy bundles.

Attestation

SOC 2 Type II

All five trust criteria. Control objectives include CC6.3 (logical access control) and CC7.2 (system monitoring and incident detection). Automated quarterly evidence packaging.

Cloud assurance

CSA STAR Level 2

Cloud Security Alliance Security Trust Assurance Registry — designed to the third-party attestation model against the Cloud Controls Matrix.

Framework

NIST CSF 2.0

Cybersecurity Framework alignment across Govern, Identify, Protect, Detect, Respond, Recover.

Controls baseline

NIST 800-53 Rev. 5

Moderate baseline by default. High baseline available for sensitive-data deployments. Continuous monitoring per OSCAL.

Hardening

CIS Benchmarks

CIS Benchmarks enforced via Kyverno (Kubernetes policy) and OpenSCAP (host configuration).

EU financial sector

DORA

Digital Operational Resilience Act — incident timelines, resilience testing, third-party ICT-provider register.

Deployment- or vertical-dependent

Activated per tenant profile.

The following controls switch on for specific deployments or data classifications, not as universal defaults.

US federal

FedRAMP Moderate / High

Sovereign GovCloud profile with FIPS 140-3 cryptography.

US healthcare

HIPAA / HITECH

PHI boundary enforced at the data-classification layer. Business Associate Agreements (BAAs) issued per tenant. Activates only on PHI-tagged data — no implicit elevation.

US law enforcement

CJIS

Criminal Justice Information Services controls for tenant deployments handling CJI data.

US education

FERPA

Student-record boundary enforced. Education-record tagging governs access, retention, and disclosure. Parental and eligible-student rights honoured.

P/03 · Payment & financial

Scoped narrow. Verified by invariant.

Card data

PCI DSS v4.0 · SAQ-A

Deliberately scoped to SAQ-A by never touching card numbers — provider iframes only. Integration tests assert no PAN ever reaches the server. The invariant is the control.

EU authentication

PSD2 / SCA

Strong Customer Authentication via 3D Secure 2 (3DS2) for EU cardholders. Exemption logic where regulatorily permitted.

India payments

RBI requirements

INR payment-data localisation to the India region (ap-south-1). Network tokenisation. Card-on-File compliance per RBI mandate. Cyber Security Framework requirements enforced.

Financial crime

AML / KYC

Sanctions and PEP screening per FATF guidance. Records retained ≥ 5 years per FATF / RBI requirements.

P/03b · Financial & trading retention

Books-and-records regimes for regulated finance.

Where the tenant operates as a broker-dealer, investment firm, or regulated counterparty, tapestree's immutable archive satisfies the long-retention regimes below by default.

US broker-dealer

FINRA 4511

Books-and-records preservation across the firm's required records — communication, customer accounts, order tickets — for the duration prescribed by the related FINRA rule set.

US securities

SEC 17a-4(f)

Electronic records preservation in non-rewriteable, non-erasable format (WORM-equivalent). Object Lock retention, cryptographic hash chain, and tertiary backup satisfy the modernised 17a-4(f) criteria.

EU investment firms

MiFID II

5-year (extendable to 7) retention for client communications and order records. Voice and electronic communication recording covered where in scope.

EU operational resilience

DORA

Incident timelines, resilience testing, third-party ICT-provider register. Binds EU financial-sector tenants; controls already engineered in.

US financial crime

FinCEN · BSA

Bank Secrecy Act suspicious-activity reporting (SAR) workflow. Currency Transaction Reports (CTR). 5-year minimum retention.

Global AML

AML / KYC · FATF

Sanctions and PEP screening. ≥ 5-year retention per FATF and RBI guidance. Continuous transaction-monitoring rule sets.

P/04 · AI governance

AI as a governed system, not an unregulated tool.

tapestree's agentic features (tapHistory, AI deal coaching, AI clause review, predictive workflows) operate under explicit governance gates — human approval authority, eval-harness promotion gates, full audit of every agent step.

EU regulation

EU AI Act

Risk-class register maintained per Annex III high-risk classifications. Article 12 (record-keeping), 14 (human oversight), 17 (quality management), and 73 (serious-incident reporting) obligations implemented. Transparency obligations met for general-purpose AI components.

US framework

NIST AI RMF 1.0

AI Risk Management Framework — Map, Measure, Manage, Govern functions implemented across the AI development lifecycle.

Management system

ISO/IEC 42001:2023

AI Management System (AIMS) designed to ISO 42001 — the operational backbone for AI governance, complementing the ISO 27001 ISMS.

P/05 · Communication recording

All-party / two-party consent honoured by jurisdiction.

tapestree's voice, video, and screen-recording features apply the strictest consent rule that applies to any participant — never the loosest.

United States · all-party-consent states

CA · FL · IL · MD · MA · MT · NH · PA · WA

For meetings, calls, and any electronic communication recording where any participant is in one of these states, explicit all-party consent is collected and stored as part of the immutable archive.

EU · UK · Canada · India

Two-party / all-party regimes

For meetings with participants in the EU, UK, Canada, or India, equivalent recording-consent obligations are enforced — covering GDPR Art. 6 lawful basis, UK GDPR, PIPEDA, and DPDP Act consent provisions.

How it is enforced

Compliance as machinery, not posture.

The frameworks above are enforced through the following platform mechanisms — not through promises in a deck.

Retention

MAX-rule resolver

When multiple regimes apply to the same record, the longest applicable retention wins. No silent expiry. No regime-shopping.

Immutable archive

Object Lock · hash chain · Rekor

Records preserved in non-rewriteable storage (Object Lock), with cryptographic hash chain and transparency-log entries (Rekor) for tamper-evidence.

Policy enforcement

OPA policy bundles

Open Policy Agent bundles encode access, retention, and disclosure rules. Every read and write path is policy-gated.

Information rights

IRM

Information Rights Management on exported documents — view, copy, print, and forward controls survive the perimeter.

Evidence

compliance-evidence skills

Automated evidence packaging for SOC 2, ISO 27001, FedRAMP, CSA STAR, PCI DSS, AML, DORA, and AI frameworks. Quarterly cadence by default.

Change discipline

Compliance-Impact PR trailer

Every pull request must declare its compliance impact (touched controls, frameworks affected, evidence delta). Mandatory CI gate.

Note on claims

Architected for, not certified to — unless stated.

The frameworks listed above are what tapestree is architected and governed to support. Actual certification or attestation status — where an external auditor has signed off — is shared with prospective customers and partners under NDA. Where no certification exists yet, the platform meets the equivalent control specification by construction.

Observations worth flagging

Two invariants we test continuously.

Invariant 01

PCI SAQ-A scope depends on PAN-isolation.

The SAQ-A claim rests on a hard invariant: no Primary Account Number ever reaches a tapestree server. Agentic and workflow features (including any agent step reading a payment-provider webhook) must not silently break it. Continuous integration tests assert PAN-isolation.

Invariant 02

DORA binds only EU financial-sector tenants.

But the underlying controls — incident timelines, resilience testing, third-party register — are already engineered in. Claiming DORA is therefore low-cost and useful for EU financial customers.

Need the full posture?

Request our security & compliance pack.

Certifications, attestations, evidence summaries, and architecture diagrams. Available under NDA to qualified prospects.

Request the pack Contact us