tapestree is built to meet the privacy, security, payment, and AI-governance bar that enterprise customers and regulators require — and every tenant gets that floor, from a single user upward. It is not an enterprise upsell you unlock later. The heavier, sector-specific regimes below activate per deployment and per vertical; the baseline is the same for everyone.
Erasure cascades across all stores. Records of Processing Activities (ROPA) maintained. Breach workflow with ≤ 72h notification timer.
Do-not-sell honoured. Global Privacy Control (GPC) signals respected. Consumer-rights workflow integrated.
Consent manager, multilingual notices, minor-data flags, cross-border transfer allowlists. Aligned to the regulatory floor of the founding region.
Personal Information Protection and Electronic Documents Act compliance for Canadian deployments.
Lei Geral de Proteção de Dados — controller and processor obligations, data-subject rights, ANPD reporting.
Privacy Information Management System (PIMS) layered on the ISMS — extends ISO 27001 controls with privacy-specific obligations.
Information Security Management System designed to the ISO 27001 control set — with the cloud extensions 27017 (cloud-specific controls) and 27018 (PII in public clouds). Annex A.5.18 (access rights) enforced via OPA policy bundles.
All five trust criteria. Control objectives include CC6.3 (logical access control) and CC7.2 (system monitoring and incident detection). Automated quarterly evidence packaging.
Cloud Security Alliance Security Trust Assurance Registry — designed to the third-party attestation model against the Cloud Controls Matrix.
Cybersecurity Framework alignment across Govern, Identify, Protect, Detect, Respond, Recover.
Moderate baseline by default. High baseline available for sensitive-data deployments. Continuous monitoring per OSCAL.
CIS Benchmarks enforced via Kyverno (Kubernetes policy) and OpenSCAP (host configuration).
Digital Operational Resilience Act — incident timelines, resilience testing, third-party ICT-provider register.
The following controls switch on for specific deployments or data classifications, not as universal defaults.
Sovereign GovCloud profile with FIPS 140-3 cryptography.
PHI boundary enforced at the data-classification layer. Business Associate Agreements (BAAs) issued per tenant. Activates only on PHI-tagged data — no implicit elevation.
Criminal Justice Information Services controls for tenant deployments handling CJI data.
Student-record boundary enforced. Education-record tagging governs access, retention, and disclosure. Parental and eligible-student rights honoured.
Deliberately scoped to SAQ-A by never touching card numbers — provider iframes only. Integration tests assert no PAN ever reaches the server. The invariant is the control.
Strong Customer Authentication via 3D Secure 2 (3DS2) for EU cardholders. Exemption logic where regulatorily permitted.
INR payment-data localisation to the India region (ap-south-1). Network tokenisation. Card-on-File compliance per RBI mandate. Cyber Security Framework requirements enforced.
Sanctions and PEP screening per FATF guidance. Records retained ≥ 5 years per FATF / RBI requirements.
Where the tenant operates as a broker-dealer, investment firm, or regulated counterparty, tapestree's immutable archive satisfies the long-retention regimes below by default.
Books-and-records preservation across the firm's required records — communication, customer accounts, order tickets — for the duration prescribed by the related FINRA rule set.
Electronic records preservation in non-rewriteable, non-erasable format (WORM-equivalent). Object Lock retention, cryptographic hash chain, and tertiary backup satisfy the modernised 17a-4(f) criteria.
5-year (extendable to 7) retention for client communications and order records. Voice and electronic communication recording covered where in scope.
Incident timelines, resilience testing, third-party ICT-provider register. Binds EU financial-sector tenants; controls already engineered in.
Bank Secrecy Act suspicious-activity reporting (SAR) workflow. Currency Transaction Reports (CTR). 5-year minimum retention.
Sanctions and PEP screening. ≥ 5-year retention per FATF and RBI guidance. Continuous transaction-monitoring rule sets.
tapestree's agentic features (tapHistory, AI deal coaching, AI clause review, predictive workflows) operate under explicit governance gates — human approval authority, eval-harness promotion gates, full audit of every agent step.
Risk-class register maintained per Annex III high-risk classifications. Article 12 (record-keeping), 14 (human oversight), 17 (quality management), and 73 (serious-incident reporting) obligations implemented. Transparency obligations met for general-purpose AI components.
AI Risk Management Framework — Map, Measure, Manage, Govern functions implemented across the AI development lifecycle.
AI Management System (AIMS) designed to ISO 42001 — the operational backbone for AI governance, complementing the ISO 27001 ISMS.
tapestree's voice, video, and screen-recording features apply the strictest consent rule that applies to any participant — never the loosest.
For meetings, calls, and any electronic communication recording where any participant is in one of these states, explicit all-party consent is collected and stored as part of the immutable archive.
For meetings with participants in the EU, UK, Canada, or India, equivalent recording-consent obligations are enforced — covering GDPR Art. 6 lawful basis, UK GDPR, PIPEDA, and DPDP Act consent provisions.
The frameworks above are enforced through the following platform mechanisms — not through promises in a deck.
When multiple regimes apply to the same record, the longest applicable retention wins. No silent expiry. No regime-shopping.
Records preserved in non-rewriteable storage (Object Lock), with cryptographic hash chain and transparency-log entries (Rekor) for tamper-evidence.
Open Policy Agent bundles encode access, retention, and disclosure rules. Every read and write path is policy-gated.
Information Rights Management on exported documents — view, copy, print, and forward controls survive the perimeter.
Automated evidence packaging for SOC 2, ISO 27001, FedRAMP, CSA STAR, PCI DSS, AML, DORA, and AI frameworks. Quarterly cadence by default.
Every pull request must declare its compliance impact (touched controls, frameworks affected, evidence delta). Mandatory CI gate.
The frameworks listed above are what tapestree is architected and governed to support. Actual certification or attestation status — where an external auditor has signed off — is shared with prospective customers and partners under NDA. Where no certification exists yet, the platform meets the equivalent control specification by construction.
The SAQ-A claim rests on a hard invariant: no Primary Account Number ever reaches a tapestree server. Agentic and workflow features (including any agent step reading a payment-provider webhook) must not silently break it. Continuous integration tests assert PAN-isolation.
But the underlying controls — incident timelines, resilience testing, third-party register — are already engineered in. Claiming DORA is therefore low-cost and useful for EU financial customers.
Certifications, attestations, evidence summaries, and architecture diagrams. Available under NDA to qualified prospects.