compliance
What Divelai supports, and what it doesn’t
Divelai helps meet specific controls in each framework below. No tool makes an organisation compliant — compliance is a property of your programme, and any vendor claiming otherwise is selling you a problem for later.
Read this first
This table describes controls Divelai is designed to support. Divelai is in closed beta and holds no third-party certification — not SOC 2, not ISO 27001 — so nothing here has been verified by an external auditor. A row naming a framework means the product addresses controls within it, never that Divelai is certified against it.
| Framework | Relevant controls | How Divelai supports them |
|---|---|---|
| GDPR | Art. 5(1)(c) minimisation · Art. 25 data protection by design · Art. 30 records · Art. 32 security of processing · Ch. V transfers | Pseudonymisation at the egress boundary is named in Art. 32 as a safeguard. Data-flow maps produce Art. 30 records from actual traffic. Transfer logs evidence what crossed a border and under which policy. |
| CCPA / CPRA | Purpose limitation · service provider obligations · sensitive personal information limits | Per-destination policy restricts what each service provider receives. Token scoping supports limits on the use of sensitive personal information. |
| HIPAA | §164.502(b) minimum necessary · §164.514 de-identification · §164.312 technical safeguards | Detectors cover the 18 Safe Harbor identifier categories. Whether a given output meets the de-identification standard depends on your data and needs your own determination. |
| PCI DSS v4.0 | Req. 3 protect stored account data · Req. 4 protect in transit · scope reduction | Card data is detected by pattern plus Luhn and can be redacted before reaching any system, which supports keeping downstream systems out of scope. Divelai is not a substitute for a QSA assessment. |
| SOC 2 | CC6 logical access · CC7 monitoring · Confidentiality criteria | Append-only, hash-chained transformation records and drift alerting give an auditor evidence that controls operated over the period, not just that they existed. |
| ISO 27001 | A.8.10 information deletion · A.8.11 data masking · A.8.12 data leakage prevention | A.8.11 is data masking specifically; Divelai is a direct implementation. A.8.12 covers the egress control the sidecar performs. |
| NIST AI RMF | Govern 1.2 · Map 3 · Measure 2.7 · Manage 2.2 | Policy versioning and audit records support governance and measurement of AI data handling as a documented, testable practice. |
| EU AI Act | Art. 10 data governance · Art. 12 logging · Art. 26 deployer obligations | Deployers must govern input data and keep logs. Divelai produces both at the point data enters a model. |
Read this before quoting the table
These are the controls Divelai touches, described as accurately as we can. They are not legal advice, they are not a gap assessment of your programme, and the mapping does not transfer any obligation from you to us. Your counsel and your assessor decide what satisfies a requirement.