Docs / Trust and compliance
ARCHITECTURE CONTROLS DOCUMENTED — CERTIFICATIONS NOT CLAIMED
⏱️ 2 min read · 326 words
Trust and compliance
DenialOS documents technical controls rather than making unsupported certification claims.
Supported control areas
- tenant/client authorization;
- audit history;
- source lineage/provenance;
- least-privilege integration scopes;
- secret-reference patterns;
- private object storage;
- PHI-minimal operational telemetry;
- governed AI access;
- production preflight;
- worker/database operational controls.
- SOC 2 certification;
- HIPAA certification;
- a signed customer BAA;
- a vendor BAA;
- production security certification.
Compliance status
The repository does not establish:
BAA/DPA/legal status must be established contractually before real PHI processing with the relevant providers.
Data retention
Provider/storage-specific retention settings are deployment/customer responsibilities unless explicitly represented in an active product contract.