AI Compliance

Compliance evidence from what your agents actually did.

Reviewers do not ask what your AI policy says. They ask who used the agent, what it did, where the data went and which controls applied. InferenceFort records the answer for every governed call.

The questions reviewers ask

QuestionEvidence InferenceFort records
Who used the agent?User, agent and customer identity on every event.
What did it do?Model calls and tool calls, linked into one trace per request, including across agents.
Where did the data go?The resolved provider and destination of every call.
Was sensitive data protected?PHI classes detected and redacted, with the placeholders the model saw instead.
Which controls applied?The rule that decided, the findings, and the list of content scopes that were screened.
What was not covered?Capability gaps: controls that were configured but could not run.

Evidence that does not overstate

A control that did not run must never look like a control that found nothing. InferenceFort reports what it could not do: a detector that could not be built, PHI classes outside its pattern coverage, or a detection stage unavailable in offline mode. Check governance_status()["capability_gaps"] at deploy time and review gaps alongside findings.

Data residency

Egress policy pins each model provider to approved endpoints or regions and blocks other destinations before the prompt leaves the process. The destination is recorded on every event as a receipt. InferenceFort enforces the configured destination, not packet routing, so pair it with your network egress controls.

Protected health information

When enabled, redaction runs before the model call. Shaped identifiers such as SSNs, card numbers, phone numbers, email addresses, dates, ZIP+4 codes, VINs and medical record numbers are replaced with typed placeholders like [SSN]. Content rules still see the original text, so a policy can block on it.

Names and places need NER. No pattern reliably finds patient names or geography. Register an NER redactor such as Microsoft Presidio, which runs on top of the built-in redaction. Until one is registered, the gap is reported on every redaction, even a successful one.

Send it to the tools you already audit with

DestinationFormat and content
Hosted audit trailFull events in the InferenceFort dashboard, including prompt and response text.
Splunk or any HTTP collectorThe same event envelope and batching, sent to your endpoint.
Local NDJSON fileFull fidelity, including prompt content. Suited to development and offline deployments.
CEF (ArcSight, QRadar, Splunk)One line per event. Never carries prompt text. Severity block = 8, flag = 5, allow = 1; signature IDs are kind:decision for correlation rules.
Evidence supports an assessment; it is not a certification. InferenceFort records runtime evidence you can use for reviews against frameworks such as HIPAA, SOC 2, ISO/IEC 42001 and the EU AI Act. It does not by itself make a system compliant.

Frequently asked questions

Does the audit trail store prompts?

The hosted trail and the local NDJSON sink include prompt and response text. The CEF format never does, because SIEM stores are long-lived and widely readable.

Can we keep all records on our own infrastructure?

Yes. Offline mode with a policy file makes no network calls to InferenceFort, and a file or SIEM sink becomes the audit record. Session-based detection requires an account.

Is HIPAA redaction on by default?

No. PHI redaction is off until policy enables it, and it reports the classes it cannot cover.

Keep reading

Design your evidence walkthrough

Bring one agent workflow, the data it touches, and the actions you need to control. As a design partner, you shape the evaluation and review the policy decisions with our engineers.

Become a design partner →