Ginkgo-AI
Book a Demo Request a Briefing
Home  /  About Us  /  Trust Center
Trust Center

Compliance is enforced at runtime.
Not reported after.

The Trust Center documents how Governed Intelligence powered by METIS™ addresses the regulatory frameworks your organization answers to — and how the control plane enforces those controls on every interaction, not in a quarterly audit.

How governance works

Every framework addressed at the Governance & Policy layer. Every interaction evidenced.

Most compliance tools document what happened. The control plane prevents non-compliant interactions from completing. Every framework below is addressed by specific controls enforced at the Governance & Policy layer and evidenced by the tamper-evident audit ledger that begins from the first interaction.

Healthcare

HIPAA & HITECH

PHI is classified at ingestion before it enters the control plane. Classification labels govern which models can process it, which users can access it, and what can be returned. BAA-ready architecture — the control plane is designed to operate as a Business Associate.

  • PHI classification enforced at ingestion
  • Every PHI access event logged with actor attribution and policy version
  • Output filtering prevents PHI surfacing to unauthorized users
  • BAA-ready — designed for covered entity compliance
Federal & Law Enforcement

FedRAMP & CJIS

Deployment options for IL4 and IL5 environments. Air-gap ready configuration for disconnected operations. CJIS Security Policy controls mapped to the Governance layer.

  • IL4/IL5 deployment options available
  • Air-gap ready — full governance in disconnected environments
  • CJIS Security Policy controls mapped to the Governance & Policy layer
  • No data traverses outside the authorized boundary
Privacy

GDPR & CCPA

Data residency controls enforced at the infrastructure and governance layer simultaneously. Right-to-erasure hooks allow data subject requests to be actioned against the connector registry without requiring model retraining.

  • Data residency controls enforced at governance layer
  • Right-to-erasure hooks in the connector registry
  • Consent management integrated into data classification
  • Cross-border transfer controls enforced by Argus Integration Server
AI Risk Management

NIST AI RMF

All four NIST AI RMF core functions operationalized in the control plane — not documented in a spreadsheet.

  • GOVERN: Policy declared, versioned, enforced on every interaction
  • MAP: Risk mapping is continuous — live posture, not a snapshot
  • MEASURE: Every interaction produces a measurement event
  • MANAGE: Kill-switch capability allows immediate connector revocation
Education

FERPA

Student record classification enforced at ingestion. Consent-scoped access governed at runtime. IRB-compatible audit trails for research institutions.

  • Student records classified and access-controlled at ingestion
  • Consent-scoped data access enforced at runtime
  • Every student record access produces a logged disclosure event
  • IRB-compatible audit trails for research populations
The audit guarantee

100% of interactions governed. Day 1 audit readiness.

100%
of interactions governed — not sampled, not reviewed in batch
0
ungoverned paths through the control plane — no bypass mode exists
Day 1
audit readiness — the evidence trail begins from the first interaction

This page documents control plane architecture and governance posture. It does not constitute a legal certification, compliance attestation, or regulatory approval. Organizations should engage qualified legal and compliance counsel to assess their specific obligations. Ginkgo-AI can provide technical documentation to support compliance assessments on request.

Request compliance documentation.

We can provide technical documentation to support your compliance assessment, security review, or procurement process.

Contact Us Request an Executive Briefing