Security · Regulation · Compliance

AI security and regulation, built to be shown

Security and regulation are converging on one demand: prove it. The work here is built for that world — local-first and data-sovereign, secure by construction, and governed so every action is lawful, explainable, reversible, and evidenced on demand. For teams shipping AI into HIPAA, PCI-DSS, GDPR, and the EU AI Act.

HIPAA PCI-DSS GDPR NIST CSF 2.0 EU AI Act SOC 2 ISO 27001 HL7 / FHIR Zero-Trust Local-First / Data Residency

The question isn't "can the AI do it?" — it's can you show what it did, prove it was lawful, and undo it?

A regulator calls on a Tuesday. Who owns the risk in the system that failed, what control was supposed to treat it, where is the evidence it actually worked, and when did the board last look. An organization either has those answers within reach or it does not — and the distance between the two is the whole game. The systems built and studied here treat that chain of evidence as the product, not an afterthought.

The frame

Four surfaces of technology responsibility

Read the study →

Lawful

Do we meet the statutory and contractual obligations that govern our data and systems? Owned by Legal, Compliance, and the DPO.

Secure

Are confidentiality, integrity, and availability protected against credible threats? Owned by the CISO and Security Engineering.

Ethical

Are outcomes fair, transparent, and open to human oversight — especially where systems decide about people? Owned by Product, Risk, and the AI board.

Accountable

Is ownership clear, and can every claim above be evidenced on demand? Owned by the Board, Executive, and Internal Audit.

Flagships

The frame, and the systems that live inside it

Study · Compliance & Security · Reference

Technology Responsibility

A study of the duty to build and run technology that is lawful, secure, ethical, and accountable — mapping the regulatory lattice (GDPR, NIST CSF 2.0, the EU AI Act, SOC 2, ISO 27001) to the controls that satisfy it, with a maturity model and breach-clock realities.

ComplianceSecurityWPR-DAT-006
System · REEF · Active

REEF

Governed network defense: a named fleet of sensors reports to an E-2 Hawkeye AWACS that fuses corroborating signals into one high-confidence card. The Bouncer sees it, explains it, proposes the fix — and acts only on your approval, every change PIN-gated, backed up, and reversible.

PythonOPNsenseSelf-Defending

Why it fits

Local-first is a data-governance strategy

Data never leaves the box

MAX3, REEF, and FeedHacker run entirely on-premise. No third-party processor, no cloud egress of PII/PHI — the smallest possible breach surface and the simplest possible data-residency story.

Auditable by construction

Actions are logged with provenance and rationale. The evidence that satisfies an auditor falls out of operating the system, not reconstructed under pressure after an incident.

Reversible & approval-gated

Changes are proposed, not imposed — PIN-gated, backed up, and reversible. Automation stays inside human authority.

Built from real regulated work

Grounded in 25+ years across a $3.1B multi-brand health plan and Series A–C EHR/RCM systems — patterns that survived real audits, not whiteboard theory.

Engage

Building AI where the rules are real?

If you're bringing agents or automation into a regulated environment — HIPAA, PCI, GDPR, the EU AI Act — and it has to survive an audit, that's the work.

This site: HTTPS only · no third-party trackers · no analytics cookies · security.txt