AI Compliance
Compliance evidence from what your agents actually did.
Reviewers do not ask what your AI policy says. They ask who used the agent, what it did, where the data went and which controls applied. InferenceFort records the answer for every governed call.
The questions reviewers ask
| Question | Evidence InferenceFort records |
|---|---|
| Who used the agent? | User, agent and customer identity on every event. |
| What did it do? | Model calls and tool calls, linked into one trace per request, including across agents. |
| Where did the data go? | The resolved provider and destination of every call. |
| Was sensitive data protected? | PHI classes detected and redacted, with the placeholders the model saw instead. |
| Which controls applied? | The rule that decided, the findings, and the list of content scopes that were screened. |
| What was not covered? | Capability gaps: controls that were configured but could not run. |
Evidence that does not overstate
A control that did not run must never look like a control that found nothing. InferenceFort reports what it could not do: a detector that could not be built, PHI classes outside its pattern coverage, or a detection stage unavailable in offline mode. Check governance_status()["capability_gaps"] at deploy time and review gaps alongside findings.
Data residency
Egress policy pins each model provider to approved endpoints or regions and blocks other destinations before the prompt leaves the process. The destination is recorded on every event as a receipt. InferenceFort enforces the configured destination, not packet routing, so pair it with your network egress controls.
Protected health information
When enabled, redaction runs before the model call. Shaped identifiers such as SSNs, card numbers, phone numbers, email addresses, dates, ZIP+4 codes, VINs and medical record numbers are replaced with typed placeholders like [SSN]. Content rules still see the original text, so a policy can block on it.
Send it to the tools you already audit with
| Destination | Format and content |
|---|---|
| Hosted audit trail | Full events in the InferenceFort dashboard, including prompt and response text. |
| Splunk or any HTTP collector | The same event envelope and batching, sent to your endpoint. |
| Local NDJSON file | Full fidelity, including prompt content. Suited to development and offline deployments. |
| CEF (ArcSight, QRadar, Splunk) | One line per event. Never carries prompt text. Severity block = 8, flag = 5, allow = 1; signature IDs are kind:decision for correlation rules. |
Frequently asked questions
Does the audit trail store prompts?
The hosted trail and the local NDJSON sink include prompt and response text. The CEF format never does, because SIEM stores are long-lived and widely readable.
Can we keep all records on our own infrastructure?
Yes. Offline mode with a policy file makes no network calls to InferenceFort, and a file or SIEM sink becomes the audit record. Session-based detection requires an account.
Is HIPAA redaction on by default?
No. PHI redaction is off until policy enables it, and it reports the classes it cannot cover.
Keep reading
Design your evidence walkthrough
Bring one agent workflow, the data it touches, and the actions you need to control. As a design partner, you shape the evaluation and review the policy decisions with our engineers.
Become a design partner →