EthiCompass

Governance Architecture

Architecture built so the evidence can’t lie.

A compliance result is only as strong as the system that produced it. Ours is a linear, fingerprinted pipeline: every artifact is verifiable by hash, and no stage can alter what came before.

What the Architecture Serves

Two axes, and the bridge between them.

Measurement axis

Scores your AI system’s behavior across 8 dimensions. Buyer-facing, framework-neutral, worldwide.

Certification axis

The 9 control areas of ISO 42001 Annex A. Auditor-facing, matched to the frameworks you report against.

The bridge between them — measured findings mapped to governance controls and per-framework evidence — is the part no output tester and no ISO auditor owns. That bridge is the architecture’s reason to exist.

A linear chain, not a black box.

The assessment moves through a fixed sequence of stages, each handing off to the next by reference.

01

Scope

02

Adversarial testing

03

Measurement

04

Certification

05

The Score Card

Each stage receives only from the one before it, and forwards by reference what the next stage needs but it did not consume.

The model that attacks is never the model that judges. Nothing grades its own work.

Interpretation never rewrites the measured numbers. The separation is enforced by the pipeline, not by policy.

The audit trail is fingerprints, not logs.

Fingerprinted, not logged

Every artifact carries a cryptographic fingerprint and is referenced by it, never copied around the system.

Tamper-evident by construction

Alter any artifact and its fingerprint changes; the receiving stage detects it on verification. The trail can't be quietly edited.

Registered and statistical

Attack traces are immutable and citable by hash, and every score traces back to the trace that produced it. Evidence is a rate over N runs, never claimed as reproducible.

The Platform

One edge, async by design, isolated per tenant.

One uniform edge

The platform doesn't distinguish your own application's backend from a direct API integration. Both start work and register a webhook, and both are treated identically.

Async by default

Work is enqueued and acknowledged immediately; results return through signed webhooks, with a status query as a polling fallback. A run is running or done, full or partial — a partial run is honest, not an error.

Isolated per tenant

Every operation on a run checks that the caller's tenant matches the tenant stamped on the resource. One tenant's run is untouchable by another.

Gated by capability

What a run can do is decided by an entitlement snapshot of features and limits, frozen by fingerprint at creation — so a run behaves consistently for its whole life, gated by capability, never by a tier label in a token.

Same engine. Two commitments.

Proof · Cloud

A one-time technical assessment

Scope, adversarial testing, measurement, and a Score Card for your AI system. No framework certification.

  • The full scope, test, measure, and Score Card path
  • Registered, hash-citable attack traces
  • An auditable coverage report

Proof · On-premise

Continuous certification

The same path, wrapped by a human attestation gate on the way in and framework matching on the way out.

  • Everything in Proof · Cloud
  • Readiness per framework (ISO 42001, EU AI Act), with four honest gap states
  • On-prem deployment, with a year of assistance and support

Architecture is a promise.
Ask us to prove it.