SOC 2 Type II
Maps every agent action to trust service criteria CC6.x, CC7.x, CC9.x
SIGNED EVIDENCE PACKAGES
Cryptographically signed. Blockchain-anchored. Auditor-ready.
EVIDENCE PACKAGE PREVIEW
Issued 2026-05-06 14:23:08 UTC · Tenant acme-corp · sha256 e3b0c44...f59c
| ACTION | AUTHORIZATION | OBLIGATION | STATUS |
|---|---|---|---|
| fetch_credit_score | scope: read; policy: hipaa-package | HIPAA § 164.312(b)(1) | Satisfied |
| compose_decision | scope: write; bounded by policy v1.0.0 | SR 26-2 § VI, Model Inventory | Satisfied |
| notify_applicant | scope: communicate; channel: email | EU AI Act Art. 50 | Satisfied |
| store_decision | scope: persist; retention: 7 years | SOC 2 CC6.1 (TSC 2017) | Satisfied |
| escalate_to_human | scope: handoff; confidence<0.6 | EU AI Act Art. 14(4) | Gap, review required |
SIGNED BY cyphrex-signer-prod-01 (Ed25519)
PUBLIC KEY https://cyphrex.io/keys/cyphrex-signer-prod-01
ALGORITHM EdDSA · sha256 verified
TIMESTAMP Solana · hourly Merkle anchoring shipped · Core and above
BLOCKCHAIN Solana mainnet-beta · 2WCMuuf...KAMGgW
EVERY MAJOR COMPLIANCE FRAMEWORK
Maps every agent action to trust service criteria CC6.x, CC7.x, CC9.x
Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744. Article 50 transparency is in force today for systems that interact with people or generate or manipulate content. Article 4 AI literacy has applied since 2 February 2025. Expanded Article 5 prohibitions apply from 2 December 2026. High-risk obligations in Articles 9 through 15 apply to Annex III standalone systems from 2 December 2027 and to Annex I embedded systems from 2 August 2028. Mapping is not certification.
PHI access audit trail with cryptographic proof of retention compliance.
Superseded on 17 April 2026 by SR 26-2. Historical model risk programs remain mapped so prior reports stay verifiable. See the SR 26-2 card for current supervisory guidance. Mapping is not certification.
Supervisory guidance on model risk management, issued 17 April 2026 by the Federal Reserve, FDIC, and OCC. Represents sound practice; it does not set forth enforceable standards. Most relevant to banking organizations with over $30 billion in total assets. Footnote 3 places generative and agentic AI outside model scope; the institution determines appropriate governance for out of scope systems, and Cyphrex holds the evidentiary record. Also supersedes SR 21-8 on BSA/AML model risk. Mapping is not certification.
23 NYCRR Part 500 is the binding cybersecurity rule for New York regulated entities. Maps agent activity to program records, MFA, asset inventory, encryption, incident response, and 72 hour event notice. The DFS industry letter of 16 October 2024, Cybersecurity Risks Arising from Artificial Intelligence and Strategies to Combat Related Risks, interprets how Part 500 applies to AI. A further DFS AI letter was issued in May 2026. Both letters are guidance, not binding rules. Mapping is not certification.
Per-agent AML decision audit trail with identity and authorization record for BSA and FinCEN examination.
AI management system control mapping with per-agent identity and audit trail. Mapping is not certification.
In an action against a defendant who developed, modified, or used AI alleged to have caused harm, the defendant may not assert as a defense that the AI autonomously caused the harm. Other affirmative defenses, evidence relevant to causation or foreseeability, and comparative fault remain available. AB 316, Stats. 2025, ch. 672. Effective 1 January 2026.
Supervisory obligation documentation for AI agents acting on legal matters. ABA Formal Opinion 512 (2024) applies the Model Rules to generative AI and treats AI tools as nonlawyers under Rule 5.3.
22 NYCRR Part 161, effective 1 June 2026, requires disclosure and certification of AI-generated filings in New York Unified Court System courts. FRCP 11(b) is the underlying duty that filings are grounded after reasonable inquiry. ABA Formal Opinion 512 (2024) applies. Mapping is not certification.
FRCP Rule 26(g) certification of discovery responses, including TAR validation and recall. Sedona Principle 6: the responding party chooses the methodology. A per-action record of what an agent searched, reviewed, produced and excluded supports that certification. Mapping is not certification.
Books and records audit trail for AI agents in broker-dealer and RIA workflows.
Financial close audit trail with human authorizer attribution for CFO certification.
Per-agent underwriting decision documentation with identity and authorization record. As of early 2026 at least 24 states and the District of Columbia have adopted the bulletin or substantially similar guidance. The NAIC stated in December 2025 that over half of all states have adopted. Adoption is by commissioner bulletin rather than legislation.
SB 26-189 disclosure and transparency framework for automated decision-making technology that materially influences consequential decisions. Duties: pre-use consumer notice, adverse-outcome explanations within 30 days, meaningful human review, and developer documentation. Effective 1 January 2027. SB 24-205 was repealed and never took effect. Mapping is not certification.
AI risk analysis documentation with per-agent PHI identity and audit trail.
High-risk AI system conformity documentation with per-agent identity. Standalone Annex III obligations apply from 2 December 2027. Annex I embedded systems apply from 2 August 2028. Mapping is not certification.
MONITORING & ENFORCEMENT
Detects and blocks adversarial manipulation attempts against AI agents in real time. Every attempt is logged with agent identity and cryptographic proof.
Behavior profiles define what each agent is allowed to do. Actions outside that scope are blocked before execution, not flagged after.
Per-agent spending limits enforced in real time. Auto-freeze on violation. Every spend event logged with agent identity.
Detects email addresses, phone numbers, Social Security numbers, and credit card numbers in agent outputs using Luhn validation. Blocks transmission before it leaves your environment.
Scans MCP tool definitions for prompt injection, tool poisoning, unauthorized servers, and data exfiltration patterns. Trust score penalty on detection.
Compares recent agent action distribution against baseline. Flags and penalizes agents whose behavior patterns shift materially from their historical baseline.
CRYPTOGRAPHIC PROOF STACK
01
Every report is signed with our Ed25519 private key. Verify instantly against our public key registry.
02
The report content is hashed before signing. Any modification invalidates the signature.
03
Solana transaction anchor proves the report existed at a specific point in time. Cannot be backdated.
04
Hourly root on Solana, with a per-event proof of inclusion in that on-chain root. Membership of a closed leaf, not completeness.
Layers 1 and 2 ship on every report. Layers 3 and 4 ship on Core, Scale and Enterprise.
PUBLIC KEY REGISTRY
Two ways. No account. About 30 seconds.
Got a report ID from a Cyphrex evidence package? Paste it and we run four cryptographic checks against the published signing key.
Verify by ID →Downloaded a signed report? Upload the JSON file and verify it in your browser. No data is sent to Cyphrex servers, verification runs client-side.
Upload and verify →# Active signing key Key ID: cyphrex-signer-prod-01 Algorithm: Ed25519 Status: Active since 2026-05-06 Public key (PEM): https://cyphrex.io/api/keys/cyphrex-signer-prod-01 Registry (HTML): https://cyphrex.io/keys/cyphrex-signer-prod-01 # Build your own verifier View Node.js snippet at https://cyphrex.io/keys/cyphrex-signer-prod-01
Key rotation will be announced 30 days in advance. Historical keys remain available for verification.
Available on Core, Scale and Enterprise plans. Let's talk.
Let's talk. →