Compliance

Compliance-First AI Development

Anshin Aegis was designed by a former Chief Compliance Officer. Every AI capability — every prompt, every response, every model routed, every tool invoked — flows through a policy layer your Security officer helped design.

HIPAA Compliance

  • Anshin signs the Business Associate Agreement
  • Presidio PHI/PII scrub on every prompt AND every response
  • Per-tenant PostgreSQL schema isolation
  • Encryption in transit (TLS 1.2+) and at rest (LUKS + PostgreSQL TDE)
  • Immutable hash-chained per-tenant audit trail
  • Subprocessor BAAs (Anthropic, OpenAI, Google Cloud, cloud infra)
  • HIPAA compliance attestation available under NDA
  • Access controls per Anshin's app login standard

SOC 2 Readiness

Type I — Q4 2026

Audit fieldwork in progress; report expected end of Q4 2026.

Type II — Q2 2027

6-month observation period runs Q4 2026 → Q1 2027; report Q2 2027.

Interim Package

Compensating controls documentation + pen-test summary available under NDA today.

The Anna Constitution

Your enforceable AI policy. 14 Articles governing every AI interaction. Ratified v1.0.0 effective 2026-07-02. Enforced at runtime by our 32-guardrail engine. Per-tenant Constitutions available — your Compliance officer authors the specific policies your organization needs.

Read the Constitution

Regulatory Alignment

  • HIPAA (Anshin BAA)
  • HHS Executive Order 14110 (AI in healthcare)
  • State AI laws (California AB-2013, Colorado AI Act)
  • NIST AI RMF — Constitution maps to NIST profiles
  • EU AI Act (high-risk AI system provisions)
  • DPA available for EU/UK customers

See our Trust page for full documentation.

Security overview, compliance certifications, BAA template, subprocessor list, data flow diagrams, incident response commitment.