Compliance
Compliance-First AI Development
Anshin Aegis was designed by a former Chief Compliance Officer. Every AI capability — every prompt, every response, every model routed, every tool invoked — flows through a policy layer your Security officer helped design.
HIPAA Compliance
- Anshin signs the Business Associate Agreement
- Presidio PHI/PII scrub on every prompt AND every response
- Per-tenant PostgreSQL schema isolation
- Encryption in transit (TLS 1.2+) and at rest (LUKS + PostgreSQL TDE)
- Immutable hash-chained per-tenant audit trail
- Subprocessor BAAs (Anthropic, OpenAI, Google Cloud, cloud infra)
- HIPAA compliance attestation available under NDA
- Access controls per Anshin's app login standard
SOC 2 Readiness
Type I — Q4 2026
Audit fieldwork in progress; report expected end of Q4 2026.
Type II — Q2 2027
6-month observation period runs Q4 2026 → Q1 2027; report Q2 2027.
Interim Package
Compensating controls documentation + pen-test summary available under NDA today.
The Anna Constitution
Your enforceable AI policy. 14 Articles governing every AI interaction. Ratified v1.0.0 effective 2026-07-02. Enforced at runtime by our 32-guardrail engine. Per-tenant Constitutions available — your Compliance officer authors the specific policies your organization needs.
Read the ConstitutionRegulatory Alignment
- HIPAA (Anshin BAA)
- HHS Executive Order 14110 (AI in healthcare)
- State AI laws (California AB-2013, Colorado AI Act)
- NIST AI RMF — Constitution maps to NIST profiles
- EU AI Act (high-risk AI system provisions)
- DPA available for EU/UK customers
See our Trust page for full documentation.
Security overview, compliance certifications, BAA template, subprocessor list, data flow diagrams, incident response commitment.