Skip to main content

Compliance Matrix

As of Q2 2026. Mapped to product behaviors and the docs anchors that prove them.

This page exists so that GRC reviewers can answer the question "where in your platform does this control live?" without reading the entire site. Every cell links to the canonical doc page that documents the behavior.

The mapping below covers the product behaviors Trinitite is responsible for. Customer-side controls (e.g. workforce training, physical security at your offices) are out of scope and remain your responsibility. Trinitite's Trust Center covers the company-side controls (subprocessors, retention, key custody, etc.).

StatusMeaning
COVEREDThe control is implemented and observable in the platform.
PARTIALThe control is partially supported; the customer is responsible for the remainder.
SHAREDA shared-responsibility control. Trinitite provides the substrate; the customer configures it.

SOC 2 (CC, A, C, P)

ControlStatusWhere in Trinitite
CC1.x — Control environmentSHAREDTrust Center — company-side governance.
CC2.x — Communication & infoCOVEREDGlass Box Ledger, Observability.
CC3.x — Risk assessmentCOVEREDThreat Library, Test Suites, Benchmarks.
CC4.x — MonitoringCOVEREDObservability (three streams), Governance Controls.
CC5.x — Control activitiesCOVEREDGovernance Controls L0-L6.
CC6.x — Logical accessCOVEREDIdentity & RBAC, NHI Governance.
CC7.x — System operationsCOVEREDSelf-hosting, Governance Controls.
CC8.x — Change managementCOVEREDConfig-audit events in the Glass Box Ledger.
CC9.x — Risk mitigationCOVEREDFederated Defense.
A1 — AvailabilityCOVEREDSLA & Limits.
C1 — ConfidentialityCOVEREDTrust Center, TLS-in-transit, customer-managed KMS option.
P-series — PrivacyCOVEREDPII Guardian recipe, DSR for AI.

HIPAA

SafeguardStatusWhere in Trinitite
§164.308(a)(1) — Security managementSHAREDTrinitite provides the technical substrate; customer designates roles.
§164.308(a)(3) — Workforce securitySHAREDRBAC.
§164.308(a)(4) — Information accessCOVEREDRBAC, NHI Governance.
§164.308(a)(5) — Security awareness trainingSHAREDCustomer responsibility.
§164.310 — Physical safeguardsSHAREDTrust Center for company-side; customer for their environment.
§164.312(a) — Access controlCOVEREDRBAC, Sessions.
§164.312(b) — Audit controlsCOVEREDGlass Box Ledger.
§164.312(c) — IntegrityCOVEREDMerkle-chained ledger, replay verdict taxonomy.
§164.312(e) — Transmission securityCOVEREDTLS 1.3, mTLS optional.
§164.514 — De-identificationCOVEREDPII Guardian recipe.
BAACOVEREDAvailable to enterprise customers.

GDPR

ArticleStatusWhere in Trinitite
Art. 5 — PrinciplesCOVEREDPurpose-limitation enforced via per-NHI scopes; minimization via PII Guardian.
Art. 6 — Lawful basisSHAREDCustomer determines lawful basis; Trinitite preserves it via the Glass Box Ledger.
Art. 15 — Right of accessCOVEREDDSR-for-AI endpoint surfaces every Guardian decision touching a subject.
Art. 17 — Right to erasureCOVEREDCrypto-shredding of subject material; ledger receipts retained as required.
Art. 22 — Automated decision-makingCOVEREDEvery Guardian decision is reviewable + replayable; human review path documented.
Art. 25 — Data protection by designCOVEREDDefault-on Guardian, default-on PII redaction, default-on retention.
Art. 30 — Records of processingCOVEREDGlass Box Ledger.
Art. 32 — Security of processingCOVEREDTLS, KMS, audit, breaker hierarchy.
Art. 35 — DPIACOVEREDTemplate + supporting evidence available in the Trust Center.

EU AI Act

RequirementStatusWhere in Trinitite
Art. 9 — Risk management systemCOVEREDThreat Library, Test Suites.
Art. 10 — Data and data governanceCOVEREDSkill Vault provenance, training-data SBOM.
Art. 12 — Record-keepingCOVEREDGlass Box Ledger.
Art. 13 — Transparency to deployersCOVEREDPer-Guardian model cards (coming in roadmap).
Art. 14 — Human oversightCOVEREDGovernance Controls L0-L6.
Art. 15 — Accuracy, robustness, cybersecurityCOVEREDArchitecture (batch-invariant determinism), Benchmarks.
Art. 17 — Quality management systemCOVEREDTrust Center.
Art. 26 — Obligations of deployersSHAREDTrinitite enables; deployer configures.
Art. 50 — Transparency obligationsCOVEREDWatermarking and disclosure helpers in Cookbook.
Regulatory change feedCOVEREDCompliance Architecture — subscribe to delegated-acts updates.

NIST AI RMF (Govern / Map / Measure / Manage)

Function — sub-functionStatusWhere in Trinitite
Govern 1.x — Policies & proceduresCOVEREDPolicy Intelligence, Governance Controls.
Govern 4.x — Roles, responsibilitiesCOVEREDIdentity & RBAC.
Map 1.x — Context establishmentCOVEREDPer-NHI tier ladder, per-tool Guardians.
Map 5.x — Impact assessmentCOVEREDThreat Library, Test Suites.
Measure 1.x — Test, evaluation, validation, verificationCOVEREDTesting & Simulation, Benchmarks.
Measure 2.x — Performance characteristicsCOVEREDObservability (RAG telemetry, replay verdict taxonomy).
Measure 3.x — Tracking emergent risksCOVEREDFederated Defense.
Manage 1.x — Risk treatmentCOVEREDGovernance Controls.
Manage 4.x — Documentation, monitoringCOVEREDGlass Box Ledger.

What's next

Trust Center — company-side controls, subprocessors, key custody.

Compliance Architecture — how the platform structures evidence.

Glass Box Ledger — the substrate every audit relies on.