> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hexr.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Compliance

> Hexr's architecture supports SOC 2, GDPR, HIPAA, and FedRAMP compliance requirements.

## Compliance Readiness

| Framework         | Status                              | Key Controls                                                  |
| ----------------- | ----------------------------------- | ------------------------------------------------------------- |
| **SOC 2 Type II** | Architecture ready                  | Encryption at rest, audit logging, access controls            |
| **GDPR**          | Architecture ready                  | Data isolation per tenant, encryption, right to deletion      |
| **HIPAA**         | Architecture ready                  | PHI isolation, audit trails, encryption                       |
| **FedRAMP**       | Roadmap — air-gap not yet available | Intended: air-gapped deployment, FIPS-compatible cryptography |

***

## Key Controls

### Encryption

| Data State         | Method                                                     |
| ------------------ | ---------------------------------------------------------- |
| In transit         | mTLS (SPIFFE SVIDs) — all service-to-service communication |
| At rest (secrets)  | AES-256-GCM (Hexr Vault)                                   |
| At rest (database) | PostgreSQL with storage-level encryption                   |
| At rest (cache)    | Valkey in-cluster only (no external access)                |

### Access Control

| Control          | Implementation                                      |
| ---------------- | --------------------------------------------------- |
| Identity         | SPIFFE per-process identity (no shared credentials) |
| Authentication   | mTLS + API key authentication                       |
| Authorization    | OPA policies at every service boundary              |
| Tenant isolation | Kubernetes namespace isolation                      |
| Data isolation   | SPIFFE-scoped secret access                         |

### Audit

| Audit Capability      | Implementation                              |
| --------------------- | ------------------------------------------- |
| Request logging       | Every request traced via OpenTelemetry      |
| Credential access     | Every STS exchange logged with SPIFFE ID    |
| Secret access         | Every Vault read/write logged               |
| LLM interactions      | Every prompt/response logged (configurable) |
| Configuration changes | Kubernetes audit logging                    |

***

## Air-Gapped Deployment

**Roadmap, not available today.** The current focus is the hybrid model: the
data plane in your cluster, a thin control plane for licensing.

The chart already accepts `cloud.enabled=false` with an offline licence, so a
data plane can run without reaching `api.hexr.cloud`. What is missing is
in-cluster delivery of framework signature packs, which are fetched over HTTPS.
An air-gapped cluster would be frozen on whichever packs shipped in its SDK
wheel.

Do not plan a FedRAMP or classified deployment around this yet. See
[Air-Gapped Deployment](/self-hosted/air-gapped) for the intended design, and
talk to us first.
