What signed evidence proves, and what it does not.
01 · THIS REPORT, NOT YOUR WHOLE PROGRAMA passing run means this JSON matches our published key, the hash, and (when present) the Solana anchor. It does not certify that every system you run is compliant end to end. Your auditor still signs the opinion. We give them receipts.
02 · OUR PATH, NOT EVERY PATHCyphrex signs what flows through our enforcement and logging. If an agent never touches our middleware, we never saw it, and this verifier will not invent coverage you did not wire up.
03 · TRUTH OF RECORD, NOT BUSINESS JUDGMENTWe bind actions, policies, and timestamps with cryptography. We do not score whether the model gave you good advice, a fair price, or the right diagnosis. That is still your review board and your domain experts.
04 · EVIDENCE FOR CONFORMITY WORK, NOT THE CONFORMITY DECISIONRegulators and notified bodies own Article 43 outcomes for Annex III systems. We ship artifacts they can inspect. We do not stand in their chair or stamp their forms for you.
FREQUENTLY ASKED
Q01 · What Is a Cyphrex Evidence Package?▾
A signed JSON or PDF report that maps each agent action to specific compliance controls. Ed25519-signed, SHA-256-bound, and anchored to Solana on Core, Scale and Enterprise when Merkle anchoring is active.
Q02 · Which Frameworks Does Cyphrex Map?▾
SOC 2 (TSC 2017), EU AI Act (Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744), HIPAA (45 CFR § 164), SR 11-7 (superseded by SR 26-2, April 2026), SR 26-2, NYDFS Part 500 (23 NYCRR), FINRA Rule 4511, SOX 302 and 906, NAIC Model Bulletin (2023), ISO 42001, Cal. Civ. Code § 1714.46 (AB 316, Stats. 2025, ch. 672), ABA Model Rules 1.1, 1.6, 5.1, 5.3 (Formal Opinion 512), Colorado ADMT Law (SB 26-189, effective 1 January 2027), AML and FinCEN (31 USC 5318), HHS OCR Phase 3, EU AI Act Annex III (high-risk from 2 December 2027), Court AI Disclosure (22 NYCRR Part 161; FRCP 11(b)), eDiscovery TAR (FRCP 26 and 34; Sedona Principles 2 and 6). Mapping is not certification. Cyphrex does not hold SOC 2 or ISO 27001 today.
Q03 · How Do I Verify Without Trusting Cyphrex?▾
Pull the raw PEM from cyphrex.io/api/keys/{keyId} (text/plain), then run Ed25519 verification locally with Node or Web Crypto. The snippet on the key page runs offline; your laptop does not need our servers to agree the signature matches. Do not fetch /keys/{keyId} into the verifier — that URL is HTML.
Q04 · What Does the Solana Anchor Prove?▾
Hourly Merkle anchoring writes the root of that hour's leaf set to a Solana transaction. A per-event proof of inclusion shows a closed leaf was in that tree. It does not prove the tree is complete — Cyphrex chooses the leaf set — and it does not cover event fields outside the closed leaf. Events from the current hour, or hours with no stored path, export as unanchored. The Ed25519 signature still covers the whole package. Solana mainnet-beta confirms in under 500ms with full finality at ~12 seconds. Anchoring runs continuously for Core, Scale and Enterprise customers. Reports without an on-chain inclusion proof still carry an Ed25519 signature and SHA-256 hash that verify independently.
Q05 · What Is Cyphrex's Signing Key?▾
cyphrex-signer-prod-01, Ed25519, active since 2026-05-06. PEM: cyphrex.io/api/keys/cyphrex-signer-prod-01. Registry: cyphrex.io/keys/cyphrex-signer-prod-01.
Q06 · Is Cyphrex a Notified Body?▾
No. We are not a law firm and we do not perform EU AI Act Article 43 conformity assessment. We produce evidence your notified body can use; we do not replace them.
Q07 · Does Cyphrex Hold SOC 2 Itself?▾
Not yet. SOC 2 Type II and ISO 27001 are on the roadmap. The Ed25519 chain and optional Solana anchor stand on their own math, independent of our own certification calendar.
Q08 · How Long Are Reports Retained?▾
Sandbox 30 days, Core 1 year, Scale 3 years, Enterprise custom retention. Download before retention ends and the file still verifies offline for as long as you keep it.