v2026.04
Read release notes
exAI Agentic OSexAI
§ 01 / 06
Compliance · audited continuouslyReports, scopes, sub-processorsFor compliance officers and auditors.
Ledger green · last verified 04:11 UTC
exAI Agentic OS · Compliance ledger

Compliance as machine-checked
evidence.

Compliance artifacts are generated from runtime signals — not reverse-engineered at audit. Every control maps to events the runtime already produces.

This page is the operator memory: every certification listed with scope, last audit date, auditor of record, and a downloadable report. Sub-processors, residency, and the evidence pipeline are below. No marketing claims — only the paperwork an auditor will actually accept.

Continuous evidenceHash-chained audit logBAAs · DPAs on file0 audit exceptions
Ledger · live
probe #04127
SOC 2 controls
0 / 92
Type II · 0 exceptions · reissued Mar 2026
ISO 27001 controls
0
Annex A clauses · 93 controls covered
Customer-managed KMS regions
0
AWS · GCP · Azure · on-prem
Audit exceptions · 12mo
0
Zero across SOC 2, ISO, HIPAA windows
evidence.stream · SIEM connector● green
Fig. 01 · ledger snapshotUpdated continuously
§ 03 / 06
Full matrix · all certifications

The whole register.
Every row, every reissue.

The unabridged compliance register. Scope, period, auditor of record, last reissue, and next assessment. FedRAMP Moderate is under 3PAO assessment with target authorization in Q3 2026 — tracked here in the same line as everything else.

CertificationScopeStatusPeriodAuditorLast reissuedNext assessmentReport
SOC 2 Type IISecurity · Availability · Confidentiality · Privacy● OperationalApr 2025 – Mar 2026A-LIGN14 Mar 2026Apr 2026 – Mar 2027download.pdf
ISO 27001:2022ISMS · Annex A · 93 controls● OperationalFeb 2025 – Feb 2027Schellman02 Feb 2026Surveillance · Feb 2027download.pdf
ISO 27701:2019Privacy IMS · GDPR aligned● OperationalFeb 2025 – Feb 2027Schellman02 Feb 2026Surveillance · Feb 2027download.pdf
HIPAA Security RulePHI · BAA · 45 CFR §164● OperationalAnnual · 2026Coalfire09 Jan 2026Jan 2027download.pdf
PCI DSS 4.0 (Level 1)SAQ-D · scoped tenants● OperationalAnnual · 2026Coalfire21 Feb 2026Feb 2027download.pdf
GDPR · DPFEU-US Data Privacy Framework● OperationalSelf-certified · 2026TrustArc · oversight11 Apr 2026Apr 2027download.pdf
CCPACal. Civ. Code §1798.100 et seq.● OperationalContinuousInternal · TrustArc-attested08 Mar 2026Continuousdownload.pdf
FedRAMP ModerateNIST 800-53 · 325 controls○ In progress3PAO assessment Q3 2026Coalfire (3PAO)ATO target Q3 2026Continuous monitoringrequest
Cyber Essentials Plus (UK)NCSC five-control baseline● OperationalAnnual · 2026IASME · accredited27 Jan 2026Jan 2027download.pdf
8 operational · 1 in-progressAnnual reissue cadence · big-4 + cybersecurity boutiqueRegister version v2026.04.18
Request full register
§ 04 / 06
Continuous evidence

Evidence is emitted,
not collected.

Every auditable event is hashed, signed, and streamed to your SIEM in machine-readable form. The control matrix maps directly onto the events the runtime already produces — no spreadsheet reconciliation, no quarterly screenshot campaigns.

Auditors traditionally receive a folder. Screenshots, CSV exports, hand-curated tickets pulled from five systems and flattened into a binder. exAI inverts that. The runtime emits a structured event for every action that touches a control — workspace boot, agent step, KMS unwrap, IdP claim, model invocation, file access. The event itself is the evidence.

Each event is hashed with SHA-256, chained to the previous event in the same tenant log, and signed with a per-region ed25519 key resident in your KMS. The chain is stored on S3-Iceberg with object-lock retention, and a copy streams in real time to your SIEM connector — Datadog, Splunk, Sentinel, Chronicle, or a customer-pull endpoint. Tampering breaks the chain; missing events break the chain. The auditor verifies the chain, not the spreadsheet.

Mapping is explicit. Every event carries a control-id field that points at the framework clause it satisfies — CC6.1 for SOC 2, A.9.4.1 for ISO 27001, §164.312(a)(1) for HIPAA. The auditor queries by control-id, gets the population back, and walks the sample with hash verification. The whole pipeline takes minutes, not weeks.

Event latency
p95 · 840ms
to SIEM connector
Chain integrity
100%
verified hourly
Retention
7 yrs
WORM · object-lock · per-tenant
evidence record · live
schema v3
Mock record · CC6.1 control evidence
  1. event-idevt_01HK6F8Q4M2RX7C5N9TZ1A0BWE
  2. control-idCC6.1 · logical access
  3. actork.mori@customer.com
  4. resourcewks-prod-01 / agent.exec
  5. timestamp2026-04-18T10:41:07.214Z
  6. hashsha256:9f4c…b27e (chained)
  7. evidence-uris3://exai-evidence/2026/04/18/evt_01HK6F8Q4M.json
  8. signatureed25519:a3e1…7c92 · attestation kms-prod-eu-west-1
Hash chain
verified
Signature
valid
Sink
SIEM
Fig. 04 · one event = one piece of evidencechain.id 9f4c…b27e
§ 05 / 06
Sub-processors & data residency

Every vendor named.
Every region pinned.

The complete sub-processor list is published — not gated, not redacted. DPAs are on file for every entry. Residency is pinned per workspace at provisioning time and enforced by the control plane; data does not migrate without an explicit, signed customer action.

Sub-processorPurposeRegionDPA on file
AnthropicFoundation model inferenceus-east-1 · eu-west-1On file · 22 Jan 2026
OpenAIFoundation model inference (opt-in)us-east-1 · eu-west-1On file · 04 Feb 2026
Google AIFoundation model inference (opt-in)us-central1 · europe-west4On file · 11 Feb 2026
AWSCompute · KMS · object-lock evidenceus-east-1 · us-west-2 · eu-west-1 · ap-southeast-1On file · 03 Mar 2025
GCPCompute · KMS · BigQuery sink (opt-in)us-central1 · europe-west4 · asia-southeast1On file · 03 Mar 2025
AzureCompute · Key Vault · sovereign tenantseastus2 · westeurope · sweden-centralOn file · 03 Mar 2025
CloudflareEdge networking · DDoS · TLSGlobal · regional WAFOn file · 18 Aug 2025
DatadogTelemetry · SIEM forwardingus-east-1 · eu-west-1 (regional)On file · 12 Sep 2025
SentryError reporting · scoped tenantsus-east-1 · eu-west-1On file · 06 Oct 2025
PagerDutyIncident on-call · 24×7 SRE rotationus-east-1On file · 14 Nov 2025
10 active sub-processors · 0 sub-sub-processorsv2026.04 · subscribe to changes
Data residency · pinned● 5 regions
  1. us-east-1region 01
    Data at rest pinned to region · KMS-local · 3AZ
    SOC 2 · HIPAA · CCPA · FedRAMP Mod (in-progress)
  2. us-west-2region 02
    Data at rest pinned to region · KMS-local · 3AZ
    SOC 2 · HIPAA · CCPA
  3. eu-west-1region 03
    Data at rest pinned to EU · DPF · KMS-local
    GDPR · ISO 27001 · ISO 27701 · DPF
  4. ap-southeast-1region 04
    Data at rest pinned to region · KMS-local · 2AZ
    ISO 27001 · MAS-TRM aligned · PDPA
  5. customer-VPCregion 05
    BYOK · BYOC · single-tenant control plane
    Customer-defined · sovereign · air-gapped
Region pinning enforced at workspace provisioning · no implicit migration
Fig. 05 · residency registerCustomer-VPC · sovereign on request
§ 06 / 06
Walkthrough · evidence packet

Bring your audit through.
We'll already have the evidence.

The evidence packet ships under NDA inside one business day. It includes the controls matrix, sample populations, the penetration test executive summary, the management response file, and a chain-verification script your auditor can run against your tenant log themselves.

SOC 2 Type IIISO 27001ISO 27701HIPAAPCI DSS 4.0GDPR · DPF
Compliance ledger · v2026.04.18Last verified 04:11 UTCcompliance@exai.dev · PGP fingerprint on request