Sovereign AI Compliance — POPIA · GDPR · SOC 2 · ISO 42001

Compliance you can prove.

The LedgerAI org-audit agent runs inside your own AWS, GCP or on-prem environment. Credentials never leave. Keys never leave. Only cryptographically signed attestations come out — verifiable by anyone, without trusting us.

YOUR INFRASTRUCTUREAGENTVERIFIER

01

Runs inside

The agent deploys into your own cloud account or data centre — Docker image, Terraform module. It connects to your systems, scores your controls, and gathers evidence where the evidence lives.

YOUR INFRASTRUCTUREAGENTVERIFIER

02

Nothing leaves

Your credentials stay in your vault. Your LLM keys stay in your environment. There is no Quantyx server in the loop — no sub-processor chain to explain to your regulator.

YOUR INFRASTRUCTUREAGENTVERIFIER

03

Only proof exits

The single output is a cryptographically signed attestation. Anyone — your auditor, your board, the FSCA — can verify it against the public verifier without trusting us.

The output is not a login. It is a document.

Audit Pack

◆ Signed — Secure Enclave

SHA-256 9f2c…41ab · pack #47

RFC 3161 timestamp · verifiable at /verify

The record only moves forward

12 MAY

Obligation added — POPIA §19 safeguards mapped to controls

26 MAY

Control passed — access review evidence attached

09 JUN

Drift detected — key-rotation claim weakened, owner alerted

16 JUN

Control repaired — rotation policy re-verified

23 JUN — CURRENT, SIGNED

Pack signed — attestation issued, timestamped, public