The proof catalogue
Pick the problem. Get the proof.
One sealed engine, a signed proof for every problem you carry. Start where it hurts, or switch to the law you answer to.
Some people know the statute. Most just know the problem. Start here.
An AI can be talked out of its rules, in one prompt or slowly across a whole conversation.
Containment. A check that sits outside the model, flags the attempt and holds it for a person, even when it is disguised or spread over many turns, and fails toward stop.
See the packs →
An agent could take an action you cannot undo. A payment, a delete, a send.
The brake. It stops the action before it runs, and if the system itself fails or goes silent, it stops too, it does not run loose. Once stopped, it stays stopped until a person re-arms it.
See the packs →
You cannot prove what your AI actually did.
The record. A tamper-evident, signed account of every decision, that anyone can check without having to trust you.
See the packs →
Is this a person or a machine?
HumanMark™. Proof of human authorship, sealed at the moment a person creates, checkable later by anyone.
See the packs →
Your data cannot leave the building.
Sovereign. It runs sealed on your own machines, local, with nothing required to leave.
See the packs →
Every problem routes to the same 114 packs and the same sealed engine. The problem lens and the law lens are two doors into one catalogue.
The proof catalogue
Pick the law. Get the proof.
One sealed engine, and a signed, self-verifying proof for every law you answer to. Search, narrow, and open any pack to see exactly what it proves.
114 packs , one engine behind every one of them.
EU AI Act · Article 50 · AI-interaction & synthetic-content transparency
EU AI Act · Arts 9/13/14/15 · Risk management, oversight, robustness, deployer info
EU AI Act · Article 12 · Automatic event logging
EU AI Act · Article 72 · Post-market monitoring
FDA · 21 CFR Part 11 · Electronic records & signatures
EU GMP · Annex 11 · Computerised-systems integrity
FDA-EMA · Good AI Practice (Jan 2026) · Data governance, performance, life-cycle management
FDA · GMLP · Good Machine Learning Practice
FDA · QMSR (21 CFR 820) · Medical-device control of records
SR 11-7 / OCC 2011-12 · Model risk management
NAIC · AI Model Bulletin · AI Systems Program & oversight
NIST · AI RMF 1.0 · Govern / Map / Measure / Manage
Colorado · SB 26-189 · Automated-decision transparency & consumer rights
NYC · Local Law 144 · Automated-hiring bias audit
California · AB 2013 · Training-data transparency
Texas · TRAIGA (HB 149) · Responsible AI governance
Utah · Title 13 Ch. 77 · Generative-AI consumer disclosure
California · AI Transparency Act · AI content disclosure & provenance
ISO/IEC 42001:2023 · AI management system (AIMS)
ISO/IEC 23894:2023 · AI risk management
C2PA · Content Credentials · Content provenance model
AICPA · SOC 2 · Trust Services Criteria evidence
ISO/IEC 27001:2022 · Information security management (ISMS)
EU · DORA (Reg 2022/2554) · Digital operational resilience
EU · NIS2 (Dir 2022/2555) · Cybersecurity risk mgmt & incident reporting
EU · Cyber Resilience Act (Reg 2024/2847) · Products with digital elements
SEC · Cyber disclosure (8-K 1.05 / Reg S-K 106) · Material cyber-incident disclosure support
CMMC Level 2 (32 CFR 170) · Defense-contractor audit & access control
PCI DSS v4.0.1 · Requirement 10 · Logging & monitoring of cardholder data access
GDPR · Article 22 · Safeguards on automated decisions
HIPAA · Security Rule · Audit controls over ePHI
Illinois · BIPA · Biometric consent & handling
GDPR · Articles 5 & 33 · Accountability & breach handling
CCPA/CPRA · consumer rights · Request handling & record-keeping
California · Delete Act (SB 362 / DROP) · Data-broker deletion processing
EU · Deforestation Regulation (Reg 2023/1115) · Due-diligence & geolocation evidence
US · UFLPA (Pub. L. 117-78) · Forced-labor supply-chain evidence
Federal Rules of Evidence · 901–902 · Court self-authentication of electronic records
EU AI Act · Arts 53 & 55 (GPAI) · General-purpose AI model obligations
EU · MDR / IVDR · Medical-device documentation, traceability & vigilance
FDA · PCCP (AI device change control) · Predetermined Change Control Plan evidence
NERC · CIP · Bulk-electric-system cybersecurity logging
FedRAMP (NIST SP 800-53 Rev 5) · US federal cloud audit & accountability
EU · eIDAS 2.0 (Reg 2024/1183) · Digital identity & trust-service records
Quebec · Law 25 (P-39.1) · Private-sector personal-information protection
India · DPDP Act, 2023 · Data-fiduciary records & breach intimation
Brazil · LGPD (Lei 13.709/2018) · Processing records, accountability & incidents
EU · CSRD / ESRS · Traceable, verifiable sustainability reporting
EU · Data Act (Reg 2023/2854) · Fair access to & use of data
EU · Product Liability Directive (Dir 2024/2853) · Software/AI product-liability evidence
China · PIPL · Personal Information Protection Law
China · Generative AI Interim Measures · Generative-AI provider obligations
US · CIRCIA (6 U.S.C. §681b) · Critical-infra incident records & preservation
NYDFS · 23 NYCRR Part 500 · Financial-services audit trail & incident notice
GLBA · Safeguards Rule (16 CFR 314) · Customer-information logging & breach notice
EU AI Act · Article 73 · Serious-incident reporting
Singapore · PDPA · Data-breach assessment & notification
Japan · APPI · Third-party records & leakage reporting
UK · GDPR / DPA 2018 · Records, security & 72-hour breach notice
South Korea · PIPA · Access-log integrity & breach notice
US · Sarbanes-Oxley (ICFR) · Internal-controls & record integrity
EU · Machinery Regulation (Reg 2023/1230) · Machinery safety & technical documentation
Canada · PIPEDA · Breach records & safeguards
Australia · Privacy Act 1988 · Notifiable Data Breaches & APPs
Switzerland · FADP (nFADP) · Processing register & breach notice
EU · Health Data Space (Reg 2025/327) · Electronic-health-data access logging
NIST · Cybersecurity Framework 2.0 · Logging, monitoring & detection
US · FERPA · Education-records disclosure log
EU · ePrivacy Directive (2002/58/EC) · Comms security, breach & cookie consent
South Africa · POPIA · Processing documentation & security compromises
Thailand · PDPA · Processing records & 72-hour breach notice
UAE · PDPL (Decree-Law 45/2021) · Breach documentation & data security
Saudi Arabia · PDPL · Breach records & 72-hour SDAIA notice
New Zealand · Privacy Act 2020 · IPPs & notifiable privacy breaches
Nigeria · NDPA 2023 · Security, accountability & 72-hour breach notice
ISO/IEC 27701:2025 · Privacy Information Management System (PIMS)
Virginia · VCDPA · Consumer data protection & assessments
Connecticut · CTDPA · Consumer data privacy & assessments
Colorado · Privacy Act (CPA) · Duty of care & data-protection assessments
Argentina · Ley 25.326 · Data security & database registration
Indonesia · PDP Law (UU 27/2022) · Processing records & 72-hour failure notice
Vietnam · PDP Law 91/2025/QH15 · PDPIA dossier & 72-hour MPS notice
Kenya · Data Protection Act 2019 · Security safeguards & 72-hour breach notice
Texas · TDPSA · Consumer data protection & assessments
Oregon · OCPA · Consumer privacy & assessments
Montana · Consumer Data Privacy Act · Controller duties & assessments
Philippines · Data Privacy Act (RA 10173) · Security & 72-hour NPC breach notice
Malaysia · PDPA (Act 709, am. 2024) · Breach notice & data protection officer
Turkey · KVKK (Law 6698) · Data security & 72-hour Board notice
China · Data Security Law (DSL) · Data security management & incident reporting
Delaware · DPDPA · Consumer data privacy & assessments
New Jersey · Data Privacy Act · Consumer privacy & assessments
Tennessee · TIPA · Consumer privacy & NIST safe harbor
Maryland · MODPA · Strong data minimization & assessments
Iowa · Consumer Data Protection Act · Controller duties & 90-day response
Nebraska · Data Privacy Act · Data minimization & assessments
Israel · Privacy Law (Amendment 13) · Data security & PPA incident notice
Indiana · Consumer Data Protection Act · Controller duties & assessments
Kentucky · Consumer Data Protection Act · Data minimization & assessments
Minnesota · Consumer Data Privacy Act · Data inventory & profiling questioning
New Hampshire · Data Privacy Act · Controller duties & assessments
Rhode Island · Data Transparency & Privacy Protection Act · Controller duties & assessments
Utah · Consumer Privacy Act (UCPA) · Controller duties & breach assistance
China · Cybersecurity Law (CSL) · Network logging & incident reporting
Florida · Digital Bill of Rights · Controller duties & assessments
Washington · My Health My Data Act · Consumer health data consent & security
EU · Digital Services Act (DSA) · Statement of reasons & transparency
US · COPPA Rule · Children's consent, security & retention
US · Fair Credit Reporting Act (FCRA) · Accuracy, permissible purpose & disputes
EU · Data Governance Act (DGA) · Data-use records & intermediation
EU · Digital Markets Act (DMA) · Gatekeeper compliance & profiling audit
US federal · DoD Responsible AI · Defense AI governance
Aviation · EASA / FAA · AI in aviation
Court · SDNY privilege / AI care-denial · Privilege survival & care-decision evidence
Don't see your exact law?
Tell us what you need to prove and the AI deployment behind it. We reply with a written scope before any call, the same engine likely already covers it, and we will scope it in writing.
Each pack maps tamper-evident evidence to a framework's controls. It is evidence input, not a compliance certification, attestation, or legal determination, and not a SOC 2 report, ISO certification, or audit opinion. Deadlines and citations are current as of the build date and should be confirmed with counsel for the relevant jurisdiction.