Compliance

Compliance is not a checkbox. It's a moat.

Sentry is built by former FedRAMP assessors and healthcare CISOs. Every framework below maps to a shipping feature — not a promise.

EU AI Act
Article 14 · Human Oversight

Every high-risk decision is logged with prompt, response, policy version, and human-reviewable evidence.

  • Automatic risk categorization
  • Article 14 logging on by default
  • Signed evidence bundles for regulators
NIST AI RMF
Govern · Map · Measure · Manage

Sentry maps directly to the NIST AI Risk Management Framework — policy authoring covers Govern; decisions cover Measure and Manage.

  • RMF-aligned policy packs
  • Continuous measurement dashboards
  • Auditable governance record
SOC 2 Type II
Security · Availability · Confidentiality

Sentry ships with tenant isolation, KMS-backed encryption at rest, and continuous availability monitoring.

  • Tenant-scoped IAM on evidence S3
  • Encryption at rest via BYOK
  • 99.95% SLA (Vanguard+)
HIPAA BAA
Protected Health Information

PHI redaction is enforced at the Gateway before any prompt reaches a provider.

  • PHI redaction policy pack
  • Signed BAA for Vanguard+
  • US-only residency option
FedRAMP
Moderate baseline → High roadmap

Citadel is designed for FedRAMP Moderate; Citadel+Enclave runs on AWS Nitro Enclaves for hardware-rooted trust.

  • Moderate accreditation in-flight
  • High roadmap for GovCloud
  • Attestation-bound policy bundles