AGICOMPLY
Client LoginBook Founder Triage
PUBLIC ASSURANCE REGISTER · VERSION 1.0

Every material claim carries its own verification boundary.

AGICOMPLY publishes the property being claimed, its implementation status, how it can be examined, the supporting evidence reference, the last review date, and the limitation a buyer must preserve.

REGISTERAGICOMPLY Public Assurance Register
VERSION1.0
LAST REVIEWEDJuly 28, 2026
CLAIMS12 bounded statements
Implemented6
Publicly demonstrated2
Available during intake1
Not currently offered3
AR-INT-001Evidence integrity
Implemented

SHA-256 content hashes are computed for evidence artifacts.

PROPERTY

The evidence-processing pipeline computes a SHA-256 digest from the uploaded file buffer and stores the resulting content hash with the evidence record.

VERIFICATION METHOD

Review the public artifact-hash demonstration or independently hash an illustrative artifact in the Evidence Review Room.

EVIDENCE REFERENCECODE-EVP-COMPUTE-SHA256 · DB-EVIDENCE-CONTENT-HASH
LAST REVIEWED

2026-07-28

LIMITATION

A matching content hash supports integrity comparison. It does not establish that the artifact is accurate, complete, current, authentic at source, or evidence of an effectively operating control.

Open public verification path
AR-LED-002Chain of custody
Implemented

Audit records are protected as append-only records.

PROPERTY

Database triggers reject UPDATE and DELETE operations against the audit record table, and row-level security policies separately deny update and delete access.

VERIFICATION METHOD

Database migration review and controlled attempt to modify or delete an audit record.

EVIDENCE REFERENCEDB-TRIGGER-PROTECT-AUDIT-LOGS · RLS-AUDIT-NO-UPDATE-DELETE
LAST REVIEWED

2026-07-28

LIMITATION

Append-only database enforcement is not the same as external cryptographic anchoring, third-party timestamping, a blockchain, or an independent attestation.

Open public verification path
AR-ID-003Tenant segregation
Implemented

Organization-scoped records are separated with Postgres row-level security.

PROPERTY

Organization identifiers are applied to tenant records and row-level security policies restrict reads and writes to the organization identifier carried in the authenticated context.

VERIFICATION METHOD

Authenticated cross-organization access-denial testing and policy review.

EVIDENCE REFERENCEDB-CURRENT-ORG-ID · RLS-ORG-SCOPED-TABLES
LAST REVIEWED

2026-07-28

LIMITATION

Database-enforced tenant separation does not by itself establish a government authorization, certification, penetration-test conclusion, or complete security posture.

Open public verification path
AR-MAP-004Evidence mapping
Implemented

Candidate evidence relationships use deterministic metadata and semantic similarity scoring.

PROPERTY

The evidence processor calculates a metadata score, a vector similarity score when embeddings are enabled, and a recorded traceability score using defined weighting logic.

VERIFICATION METHOD

Code-path review of metadata scoring, vector comparison, and final traceability calculation.

EVIDENCE REFERENCECODE-AREL-METADATA-SCORE · CODE-AREL-TRACEABILITY-SCORE
LAST REVIEWED

2026-07-28

LIMITATION

A high candidate score does not establish legal applicability, control effectiveness, factual correctness, or reviewer acceptance.

Open public verification path
AR-HUM-005Human verification
Implemented

Candidate evidence mappings can be locked or rejected by an authenticated human reviewer.

PROPERTY

Mappings move between AI_PROPOSED, HUMAN_LOCKED, and REJECTED states, with verifier identity and verification time recorded when a reviewer acts.

VERIFICATION METHOD

Authenticated verification-queue workflow and resulting status record.

EVIDENCE REFERENCEAPI-VERIFICATION-QUEUE · DB-MAPPING-VERIFIED-BY-AT
LAST REVIEWED

2026-07-28

LIMITATION

Human verification records the reviewer decision inside the defined workflow. It is not an independent audit opinion or legal determination.

Open public verification path
AR-RCE-006Decision reproducibility
Implemented

Risk-classification decisions use explicit state-machine logic and preserve a decision path.

PROPERTY

The classification engine uses coded branching logic rather than an LLM for the regulatory decision and records step identifiers, questions, responses, triggered logic nodes, timestamps, and the final determination.

VERIFICATION METHOD

Replay a supplied answer set against the same state-machine version and compare the resulting decision path.

EVIDENCE REFERENCECODE-RCE-STATE-MACHINE · DB-REGULATORY-TRIGGER-DECISION-PATH
LAST REVIEWED

2026-07-28

LIMITATION

A deterministic result reflects the implemented rule set and supplied answers. It does not replace legal interpretation or prove that the rule set covers every applicable requirement.

Open public verification path
AR-DEMO-007Reviewer examination
Publicly demonstrated

The five Baseline deliverables can be examined through a public fictional package.

PROPERTY

The public Review Room presents an illustrative Evidence Inventory, Mapping Summary, Gap Register, Ordered Remediation Plan, and Chain-of-Custody Statement.

VERIFICATION METHOD

Open the fictional package, verify artifact hashes, review all five sections, and download the structured package.

EVIDENCE REFERENCEPUBLIC-REVIEW-ROOM-ILL-RR-2026-001
LAST REVIEWED

2026-07-28

LIMITATION

The demonstration uses fictional artifacts and does not represent a customer result, legal conclusion, certification, or continuous operating assurance.

Open public verification path
AR-VER-008Package verification
Publicly demonstrated

An illustrative package manifest can be independently verified in the browser.

PROPERTY

The Package Verifier recomputes the SHA-256 hash of a canonical illustrative package manifest and compares it with the recorded manifest hash.

VERIFICATION METHOD

Use the published illustrative credentials and download the resulting verification receipt.

EVIDENCE REFERENCEPUBLIC-PACKAGE-VERIFIER-ILL-RR-2026-001
LAST REVIEWED

2026-07-28

LIMITATION

The public verifier does not query customer records. Customer-package verification is not represented as publicly enabled in this release.

Open public verification path
AR-SOW-009Engagement boundary
Available during intake

Customer-specific evidence handling and delivery terms are defined in writing.

PROPERTY

The defined AI system, review context, supplied-evidence boundary, responsible owners, transfer method, and delivery assumptions are recorded before the engagement begins.

VERIFICATION METHOD

Review the customer-specific intake confirmation and statement of work.

EVIDENCE REFERENCEINTAKE-SCOPE-CONFIRMATION · CUSTOMER-SOW
LAST REVIEWED

2026-07-28

LIMITATION

Public pages describe the standard engagement. Customer-specific obligations do not exist until documented and accepted in writing.

Open public verification path
AR-RET-010Data lifecycle
Not currently offered

Automated evidence-retention expiry and deletion enforcement.

PROPERTY

No public claim is made that retention periods, automatic expiry tracking, or policy-driven deletion are enforced by the current product.

VERIFICATION METHOD

Not applicable. This is an explicit capability boundary.

EVIDENCE REFERENCEBOUNDARY-RETENTION-AUTOMATION
LAST REVIEWED

2026-07-28

LIMITATION

Customer-specific handling expectations must be defined during intake. Do not infer automated retention enforcement from the existence of evidence storage or audit records.

AR-MON-011Continuous assurance
Not currently offered

Continuous runtime control monitoring and automated control testing.

PROPERTY

The ATO Readiness Baseline is a point-in-time evidence assessment and is not represented as a continuous monitoring service.

VERIFICATION METHOD

Not applicable. This is an explicit service boundary.

EVIDENCE REFERENCEBOUNDARY-POINT-IN-TIME-BASELINE
LAST REVIEWED

2026-07-28

LIMITATION

A completed Baseline does not prove continued operation after the assessment date or after a material system change.

AR-ATT-012Independent authority
Not currently offered

Certification, legal compliance determination, independent attestation, or authorization to operate.

PROPERTY

AGICOMPLY produces evidence packages used in procurement, authorization, customer assurance, and governance reviews. It does not issue an ATO or certify legal compliance.

VERIFICATION METHOD

Review the assessment boundary carried throughout the public site and evaluation packet.

EVIDENCE REFERENCEBOUNDARY-NO-CERTIFICATION-NO-ATO
LAST REVIEWED

2026-07-28

LIMITATION

Final legal, certification, authorization, and reliance decisions remain with the responsible customer, assessor, agency, or other authorized reviewer.

Open public verification path
REGISTER BOUNDARY

Every claim is narrower than the conclusion a reviewer may ultimately reach.

The register describes implemented properties, public demonstrations, intake materials, and explicit non-capabilities. It does not certify AGICOMPLY, replace customer due diligence, or establish that a control operated effectively in a customer environment.

PROCUREMENT USE

Carry the evidence reference and limitation into the reviewer package.

The register is designed to support due diligence and internal approval, not replace them.

Generate Approval Brief