Compliance posture
What “SOC 2-oriented” means here
FACE’s controls are designed around the concerns that SOC 2’s trust services criteria address: access control, confidentiality, change and configuration integrity, and monitoring. The earlier pages in this section describe those controls. Some rules and log fields in the code carry ISO 27001, ISO 42001, ISO 31000 or SOC 2 tags. Those tags are labels a developer attached to a control, used for classification and reporting. They are not the result of an assessment.
Compliance environment variables are declarations
FACE’s compliance analysis reads four environment variables and reports their values. None of them is a control. Each is an operator’s assertion about the deployment:
| Variable | What FACE does with it |
|---|---|
ENFORCE_AUDIT_LOGGING | Reports it. It gates nothing: audit logging is always on regardless of its value. |
REQUIRE_HITL | Reports it. No enforcement code reads it, and no action is blocked because of it. |
DATABASE_ENGINE | Reports it. It is not probed. |
PRIMARY_SERVER_URL | Reports it. It is not probed. |
FACE does not refuse to start when these variables are missing. In the analysis
prompt, each value is labelled OPERATOR DECLARATION with the variable named,
followed by a NOTE TO THE ASSESSOR explaining that a declaration is not evidence
the control exists. Where FACE can observe a fact directly, such as audit logging
being always on, it reports that fact separately as OBSERVED in code.
cmd/compliance_env_gates_test.go pins this labelling in both directions.
Setting REQUIRE_HITL=true changes the text a model reads and nothing else. The
controls that actually keep a human in the loop are the ones described in
AI safety: action judging, and the
downgrade of unapproved autonomous email to a draft.
Evidence you can check
Many of the controls in this section are enforced by a named test, so a reviewer with source access can run them:
| Control | Test |
|---|---|
| The unauthenticated surface is exactly the documented list | cmd/auth_exemptions_test.go |
| An mTLS identity never replaces a session | TestAVerifiedMTLSPeerStillNeedsABearerToken |
| No insecure gRPC transport in the command package | cmd/no_insecure_transport_test.go |
| No plaintext downgrade on runner dials | cmd/runner_dial_no_downgrade_test.go |
| Consensus is served only over mTLS | TestRaftServiceIsNeverOnTheApplicationListener |
| A revocation reaches runners | TestARevokeOnTheControlPlaneIsRefusedOnARunner |
| Lineage records carry no data values | TestNoResultValuesReachAnyLineageRecord |
Local secret-bearing files are 0600/0700 | internal/ai/servicetoken_perms_test.go |
| No service token is ever invented | TestFaceNeverInventsAServiceToken |
| Guardrail docs match the code and can fire | cmd/openbias_rule_parity_test.go and the firing tests |
| Unmapped agents cannot reach the loop | cmd/ralph_guardrail_failclosed_test.go |
| Voice refusals never reach the model, and transcripts are never logged | cmd/voice_guardrail_test.go |
| No address family is pinned | TestNothingPinsAnAddressFamily |
| Compliance env vars are labelled as declarations | cmd/compliance_env_gates_test.go |
Many of these source-scanning guards carry a positive control or a mutation test, which deliberately breaks the protected property and requires the guard to fail by name. Without one, a guard could pass while checking nothing.
What this page does not establish
- Oriented is not compliant. A control designed with SOC 2 in mind is not a control an auditor has tested over a period of time.
- Tests prove code behaviour, not operations. They say nothing about how a deployment is operated: access reviews, change management, incident response, log retention and key custody all belong to your organisation and to the platform operator.
- A compliance tag is a classification, not a finding. A rule tagged
ISO42001is a rule someone associated with that standard. Nobody has assessed it against the standard.