Skip to main content

Evidence-First Compliance

Hexr doesn’t just claim compliance — it produces signed evidence rows in your own Postgres that map every agent action to a named control. When your auditor asks what your AI agents did last Tuesday, hexr audit generates a signed PDF with the answer. Evidence stays in your cluster. Nothing is sent to Hexr’s infrastructure.

Buyer Ring → Framework Mapping


Framework Mapping

SOC 2 Type II

HIPAA §164.312 Technical Safeguards

NIST 800-53 (FedRAMP)

FFIEC (Multi-Cloud Finserv)

EU AI Act


Generating the Auditor PDF

The PDF includes:
  • Every agent action in the date range
  • SPIFFE identity of the process that triggered it
  • OPA policy result (ALLOW/DENY) and policy version
  • Compliance control it maps to
  • Cryptographic signature for tamper evidence

Encryption Summary


Key Controls

Encryption

Access Control

Audit


Framework Mapping

SOC 2 Type II

NIST AI Risk Management Framework

GDPR

HIPAA