AI.CleanCode

Compliance & Governance

Control data residency, maintain comprehensive audit trails, and map secure-development evidence to specific NIST SSDF practices. Certification status is stated plainly below.

Certifications and Status

SOC 2 Type IIIn progress — expected Q2 2027
ISO/IEC 27001Planned
GDPRData processing agreement available on request
EU AI ActAI.CleanCode is not a high-risk system under Annex III; statement available on request
Full Audit Trail
Every finding, every action
Every detection, suppression, and policy change is captured with actor, timestamp, and reasoning — exportable as audit-ready evidence for internal reviewers.
Data Residency Controls
Region of your choice
Air-Gapped On-Prem keeps source code inside your network boundary today. Single-Tenant Cloud, planned for H1 2027, will process it in a dedicated VPC.
Tenant Isolation
No shared state
Customer data is isolated at the storage, compute, and key layer. Findings and policies from one tenant are never visible to another.
Customer-managed Keys
Encryption you control
Bring your own KMS for at-rest encryption with Air-Gapped On-Prem and the planned Single-Tenant Cloud. Revoke a key, revoke our ability to read your data.

NIST SSDF Mapping

DevSecOps is the most direct way to satisfy secure-development, maintenance, and incident-response requirements.

DevSecOps ElementMaps to NIST SSDF
Shift LeftPO.1 + PW.1 — security requirements are defined up front and the design is checked against them
CI/CD SecurityPO.3 + RV.1 — implement supporting toolchains and identify vulnerabilities continuously
Security as CodePS.1 — protect all forms of code from tampering
SBOM & Supply ChainPS.3 + PW.4 — provenance data for every release and controlled reuse of third-party components
AppSec AutomationPW.7 + PW.8 — review and test code for vulnerabilities
Threat ModelingPW.1 — design software to meet security requirements and mitigate risk
DevSecOps ChampionsPO.2 — prepare people for secure development

Deployment Patterns

Capability
Managed Pilot
Single-Tenant Cloud

Planned for H1 2027 — not currently available

Air-Gapped On-Prem
InfrastructureMOAI-hosted evaluation environmentDedicated VPC (planned)Customer VPC (AWS, GCP, Azure)
Data ResidencyUS EastRegion selected at deploymentCustomer controlled
Code RetentionNever stored (in-memory only)Never stored (in-memory only)Never leaves customer network
Update CadenceContinuous (Daily)Planned: weekly / staged, after launchManual (via secure artifact sync)
Runtimes SupportedManaged by MOAIManaged by MOAILinux VM, Kubernetes, OpenShift
Who Operates ItMOAIMOAICustomer