Every material claim carries its own verification boundary.
AGICOMPLY publishes the property being claimed, its implementation status, how it can be examined, the supporting evidence reference, the last review date, and the limitation a buyer must preserve.
SHA-256 content hashes are computed for evidence artifacts.
The evidence-processing pipeline computes a SHA-256 digest from the uploaded file buffer and stores the resulting content hash with the evidence record.
Review the public artifact-hash demonstration or independently hash an illustrative artifact in the Evidence Review Room.
CODE-EVP-COMPUTE-SHA256 · DB-EVIDENCE-CONTENT-HASH2026-07-28
A matching content hash supports integrity comparison. It does not establish that the artifact is accurate, complete, current, authentic at source, or evidence of an effectively operating control.
Audit records are protected as append-only records.
Database triggers reject UPDATE and DELETE operations against the audit record table, and row-level security policies separately deny update and delete access.
Database migration review and controlled attempt to modify or delete an audit record.
DB-TRIGGER-PROTECT-AUDIT-LOGS · RLS-AUDIT-NO-UPDATE-DELETE2026-07-28
Append-only database enforcement is not the same as external cryptographic anchoring, third-party timestamping, a blockchain, or an independent attestation.
Organization-scoped records are separated with Postgres row-level security.
Organization identifiers are applied to tenant records and row-level security policies restrict reads and writes to the organization identifier carried in the authenticated context.
Authenticated cross-organization access-denial testing and policy review.
DB-CURRENT-ORG-ID · RLS-ORG-SCOPED-TABLES2026-07-28
Database-enforced tenant separation does not by itself establish a government authorization, certification, penetration-test conclusion, or complete security posture.
Candidate evidence relationships use deterministic metadata and semantic similarity scoring.
The evidence processor calculates a metadata score, a vector similarity score when embeddings are enabled, and a recorded traceability score using defined weighting logic.
Code-path review of metadata scoring, vector comparison, and final traceability calculation.
CODE-AREL-METADATA-SCORE · CODE-AREL-TRACEABILITY-SCORE2026-07-28
A high candidate score does not establish legal applicability, control effectiveness, factual correctness, or reviewer acceptance.
Candidate evidence mappings can be locked or rejected by an authenticated human reviewer.
Mappings move between AI_PROPOSED, HUMAN_LOCKED, and REJECTED states, with verifier identity and verification time recorded when a reviewer acts.
Authenticated verification-queue workflow and resulting status record.
API-VERIFICATION-QUEUE · DB-MAPPING-VERIFIED-BY-AT2026-07-28
Human verification records the reviewer decision inside the defined workflow. It is not an independent audit opinion or legal determination.
Risk-classification decisions use explicit state-machine logic and preserve a decision path.
The classification engine uses coded branching logic rather than an LLM for the regulatory decision and records step identifiers, questions, responses, triggered logic nodes, timestamps, and the final determination.
Replay a supplied answer set against the same state-machine version and compare the resulting decision path.
CODE-RCE-STATE-MACHINE · DB-REGULATORY-TRIGGER-DECISION-PATH2026-07-28
A deterministic result reflects the implemented rule set and supplied answers. It does not replace legal interpretation or prove that the rule set covers every applicable requirement.
The five Baseline deliverables can be examined through a public fictional package.
The public Review Room presents an illustrative Evidence Inventory, Mapping Summary, Gap Register, Ordered Remediation Plan, and Chain-of-Custody Statement.
Open the fictional package, verify artifact hashes, review all five sections, and download the structured package.
PUBLIC-REVIEW-ROOM-ILL-RR-2026-0012026-07-28
The demonstration uses fictional artifacts and does not represent a customer result, legal conclusion, certification, or continuous operating assurance.
An illustrative package manifest can be independently verified in the browser.
The Package Verifier recomputes the SHA-256 hash of a canonical illustrative package manifest and compares it with the recorded manifest hash.
Use the published illustrative credentials and download the resulting verification receipt.
PUBLIC-PACKAGE-VERIFIER-ILL-RR-2026-0012026-07-28
The public verifier does not query customer records. Customer-package verification is not represented as publicly enabled in this release.
Customer-specific evidence handling and delivery terms are defined in writing.
The defined AI system, review context, supplied-evidence boundary, responsible owners, transfer method, and delivery assumptions are recorded before the engagement begins.
Review the customer-specific intake confirmation and statement of work.
INTAKE-SCOPE-CONFIRMATION · CUSTOMER-SOW2026-07-28
Public pages describe the standard engagement. Customer-specific obligations do not exist until documented and accepted in writing.
Automated evidence-retention expiry and deletion enforcement.
No public claim is made that retention periods, automatic expiry tracking, or policy-driven deletion are enforced by the current product.
Not applicable. This is an explicit capability boundary.
BOUNDARY-RETENTION-AUTOMATION2026-07-28
Customer-specific handling expectations must be defined during intake. Do not infer automated retention enforcement from the existence of evidence storage or audit records.
Continuous runtime control monitoring and automated control testing.
The ATO Readiness Baseline is a point-in-time evidence assessment and is not represented as a continuous monitoring service.
Not applicable. This is an explicit service boundary.
BOUNDARY-POINT-IN-TIME-BASELINE2026-07-28
A completed Baseline does not prove continued operation after the assessment date or after a material system change.
Certification, legal compliance determination, independent attestation, or authorization to operate.
AGICOMPLY produces evidence packages used in procurement, authorization, customer assurance, and governance reviews. It does not issue an ATO or certify legal compliance.
Review the assessment boundary carried throughout the public site and evaluation packet.
BOUNDARY-NO-CERTIFICATION-NO-ATO2026-07-28
Final legal, certification, authorization, and reliance decisions remain with the responsible customer, assessor, agency, or other authorized reviewer.
Every claim is narrower than the conclusion a reviewer may ultimately reach.
The register describes implemented properties, public demonstrations, intake materials, and explicit non-capabilities. It does not certify AGICOMPLY, replace customer due diligence, or establish that a control operated effectively in a customer environment.
Carry the evidence reference and limitation into the reviewer package.
The register is designed to support due diligence and internal approval, not replace them.