What is covered where
Runtime enforcement itself, the part of the product that acts as a security control (fail-closed verification, latches on consequential actions, signed evidence, trajectory capture), is documented in the Control plane docs: see interception and audit and evidence.
Compliance
Certification programs are underway; none are complete yet, and we state them that way:- SOC 2 Type II: in progress
- HIPAA: BAA program in progress for customers handling PHI; see the PHI/PII handling model in the Evaluation docs for how the product treats PHI today
- HITRUST CSF: in progress

