Skip to content
Compliance Evidence

Compliance Evidence

Roster name: compliance.

What it does

It records evidence for the controls you claim, and flags controls whose cited implementation has gone. It never declares you compliant.

  • Checks every control in the platform’s control index against the files, folders or workflows it cites.
  • Reads a few controls closely each night and writes down the evidence an auditor will ask for.
  • Supplies a customer-safe evidence block for the release notes.

What it reads

  • The control index: the controls, the framework clauses each maps to (PCI-DSS, SOC 2, ISO/IEC 27001, ISO 31000, ISO/IEC 42001), and what each cites.
  • For the close reads, the source code each control cites.

What it produces

  • The living “Compliance status” issue: a posture per framework and every control whose citation no longer exists, listed as drift.
  • Evidence it cannot see, listed as UNVERIFIED rather than missing.
  • An evidence record per closely read control: what the code does, where, and any suggested improvement.
  • A control-evidence artifact for the audit pack.

Human oversight

A person fixes a gap or updates the index, and files the evidence. Any statement that you are compliant comes from a person and an external auditor, never from this agent. Its workflow can read the repository but not change it.

Model

Qwen3.6-35B-A3B, by Qwen, licensed Apache-2.0 (the general tier). Runink domain adaptation for this agent is planned; this release uses the base model.

Where it runs and data handling

On your Runink TIDE deployment’s own inference, on your Server or in your cloud. Source code goes to that model plane and to no third-party AI service.

Guardrails

  • Evidence, never a verdict: it is instructed not to give one, and certification and compliance-status claims in its answer (such as “compliant with SOC 2”) are removed and counted before anything is filed.
  • Unseen is not missing: evidence in a repository it cannot read is UNVERIFIED, never drift and never satisfied.
  • Cited source code is passed in as untrusted data, with chat control sequences neutralised, not as instructions. Its answer cannot carry hidden markers or tags into the report.

Limitations

  • It checks the controls in the index. A control nobody wrote down is not checked.
  • A citation that exists is not proof the control works; the close reads cover only a few controls a night.
  • It does not track vulnerable dependencies (Dependency Risk) or audit each change (Release Curator).

Evaluation

No published evaluation scores yet.

Illustrative example

Invented control. “All service-to-service traffic uses mutual TLS” cites two files, and both still exist. The evidence record: “The server’s TLS settings require and verify client certificates and set TLS 1.3 as the minimum. Suggestion: certificate lifetime is fixed in code; move it to configuration so the evidence can cite one value.”