Compliance & Governance
Control data residency, maintain comprehensive audit trails, and map secure-development evidence to specific NIST SSDF practices. Certification status is stated plainly below.
Certifications and Status
SOC 2 Type IIIn progress — expected Q2 2027
ISO/IEC 27001Planned
GDPRData processing agreement available on request
EU AI ActAI.CleanCode is not a high-risk system under Annex III; statement available on request
Full Audit Trail
Every finding, every action
Every detection, suppression, and policy change is captured with actor, timestamp, and reasoning — exportable as audit-ready evidence for internal reviewers.
Data Residency Controls
Region of your choice
Air-Gapped On-Prem keeps source code inside your network boundary today. Single-Tenant Cloud, planned for H1 2027, will process it in a dedicated VPC.
Tenant Isolation
No shared state
Customer data is isolated at the storage, compute, and key layer. Findings and policies from one tenant are never visible to another.
Customer-managed Keys
Encryption you control
Bring your own KMS for at-rest encryption with Air-Gapped On-Prem and the planned Single-Tenant Cloud. Revoke a key, revoke our ability to read your data.
NIST SSDF Mapping
DevSecOps is the most direct way to satisfy secure-development, maintenance, and incident-response requirements.
| DevSecOps Element | Maps to NIST SSDF |
|---|---|
| Shift Left | PO.1 + PW.1 — security requirements are defined up front and the design is checked against them |
| CI/CD Security | PO.3 + RV.1 — implement supporting toolchains and identify vulnerabilities continuously |
| Security as Code | PS.1 — protect all forms of code from tampering |
| SBOM & Supply Chain | PS.3 + PW.4 — provenance data for every release and controlled reuse of third-party components |
| AppSec Automation | PW.7 + PW.8 — review and test code for vulnerabilities |
| Threat Modeling | PW.1 — design software to meet security requirements and mitigate risk |
| DevSecOps Champions | PO.2 — prepare people for secure development |
Deployment Patterns
| Capability | Managed Pilot | Single-Tenant Cloud Planned for H1 2027 — not currently available | Air-Gapped On-Prem |
|---|---|---|---|
| Infrastructure | MOAI-hosted evaluation environment | Dedicated VPC (planned) | Customer VPC (AWS, GCP, Azure) |
| Data Residency | US East | Region selected at deployment | Customer controlled |
| Code Retention | Never stored (in-memory only) | Never stored (in-memory only) | Never leaves customer network |
| Update Cadence | Continuous (Daily) | Planned: weekly / staged, after launch | Manual (via secure artifact sync) |
| Runtimes Supported | Managed by MOAI | Managed by MOAI | Linux VM, Kubernetes, OpenShift |
| Who Operates It | MOAI | MOAI | Customer |
