divelai closed beta

compliance

What Divelai supports, and what it doesn’t

Divelai helps meet specific controls in each framework below. No tool makes an organisation compliant — compliance is a property of your programme, and any vendor claiming otherwise is selling you a problem for later.

Read this first

This table describes controls Divelai is designed to support. Divelai is in closed beta and holds no third-party certification — not SOC 2, not ISO 27001 — so nothing here has been verified by an external auditor. A row naming a framework means the product addresses controls within it, never that Divelai is certified against it.

FrameworkRelevant controlsHow Divelai supports them
GDPR Art. 5(1)(c) minimisation · Art. 25 data protection by design · Art. 30 records · Art. 32 security of processing · Ch. V transfers Pseudonymisation at the egress boundary is named in Art. 32 as a safeguard. Data-flow maps produce Art. 30 records from actual traffic. Transfer logs evidence what crossed a border and under which policy.
CCPA / CPRA Purpose limitation · service provider obligations · sensitive personal information limits Per-destination policy restricts what each service provider receives. Token scoping supports limits on the use of sensitive personal information.
HIPAA §164.502(b) minimum necessary · §164.514 de-identification · §164.312 technical safeguards Detectors cover the 18 Safe Harbor identifier categories. Whether a given output meets the de-identification standard depends on your data and needs your own determination.
PCI DSS v4.0 Req. 3 protect stored account data · Req. 4 protect in transit · scope reduction Card data is detected by pattern plus Luhn and can be redacted before reaching any system, which supports keeping downstream systems out of scope. Divelai is not a substitute for a QSA assessment.
SOC 2 CC6 logical access · CC7 monitoring · Confidentiality criteria Append-only, hash-chained transformation records and drift alerting give an auditor evidence that controls operated over the period, not just that they existed.
ISO 27001 A.8.10 information deletion · A.8.11 data masking · A.8.12 data leakage prevention A.8.11 is data masking specifically; Divelai is a direct implementation. A.8.12 covers the egress control the sidecar performs.
NIST AI RMF Govern 1.2 · Map 3 · Measure 2.7 · Manage 2.2 Policy versioning and audit records support governance and measurement of AI data handling as a documented, testable practice.
EU AI Act Art. 10 data governance · Art. 12 logging · Art. 26 deployer obligations Deployers must govern input data and keep logs. Divelai produces both at the point data enters a model.

Read this before quoting the table

These are the controls Divelai touches, described as accurately as we can. They are not legal advice, they are not a gap assessment of your programme, and the mapping does not transfer any obligation from you to us. Your counsel and your assessor decide what satisfies a requirement.

Need this mapped to your own control set?