Skip to content

Compliance posture

What “SOC 2-oriented” means here

FACE’s controls are designed around the concerns that SOC 2’s trust services criteria address: access control, confidentiality, change and configuration integrity, and monitoring. The earlier pages in this section describe those controls. Some rules and log fields in the code carry ISO 27001, ISO 42001, ISO 31000 or SOC 2 tags. Those tags are labels a developer attached to a control, used for classification and reporting. They are not the result of an assessment.

No certification is claimed. Nothing in this documentation states or implies that FACE, or any deployment of it, holds a SOC 2 report, ISO 27001 or ISO 42001 certification, a FedRAMP authorisation or a CMMC certification, or is suitable for ITAR-controlled data. If your procurement requires one of these, ask Runink directly. This documentation is not evidence of any of them.

Compliance environment variables are declarations

FACE’s compliance analysis reads four environment variables and reports their values. None of them is a control. Each is an operator’s assertion about the deployment:

VariableWhat FACE does with it
ENFORCE_AUDIT_LOGGINGReports it. It gates nothing: audit logging is always on regardless of its value.
REQUIRE_HITLReports it. No enforcement code reads it, and no action is blocked because of it.
DATABASE_ENGINEReports it. It is not probed.
PRIMARY_SERVER_URLReports it. It is not probed.

FACE does not refuse to start when these variables are missing. In the analysis prompt, each value is labelled OPERATOR DECLARATION with the variable named, followed by a NOTE TO THE ASSESSOR explaining that a declaration is not evidence the control exists. Where FACE can observe a fact directly, such as audit logging being always on, it reports that fact separately as OBSERVED in code. cmd/compliance_env_gates_test.go pins this labelling in both directions.

Setting REQUIRE_HITL=true changes the text a model reads and nothing else. The controls that actually keep a human in the loop are the ones described in AI safety: action judging, and the downgrade of unapproved autonomous email to a draft.

Evidence you can check

Many of the controls in this section are enforced by a named test, so a reviewer with source access can run them:

ControlTest
The unauthenticated surface is exactly the documented listcmd/auth_exemptions_test.go
An mTLS identity never replaces a sessionTestAVerifiedMTLSPeerStillNeedsABearerToken
No insecure gRPC transport in the command packagecmd/no_insecure_transport_test.go
No plaintext downgrade on runner dialscmd/runner_dial_no_downgrade_test.go
Consensus is served only over mTLSTestRaftServiceIsNeverOnTheApplicationListener
A revocation reaches runnersTestARevokeOnTheControlPlaneIsRefusedOnARunner
Lineage records carry no data valuesTestNoResultValuesReachAnyLineageRecord
Local secret-bearing files are 0600/0700internal/ai/servicetoken_perms_test.go
No service token is ever inventedTestFaceNeverInventsAServiceToken
Guardrail docs match the code and can firecmd/openbias_rule_parity_test.go and the firing tests
Unmapped agents cannot reach the loopcmd/ralph_guardrail_failclosed_test.go
Voice refusals never reach the model, and transcripts are never loggedcmd/voice_guardrail_test.go
No address family is pinnedTestNothingPinsAnAddressFamily
Compliance env vars are labelled as declarationscmd/compliance_env_gates_test.go

Many of these source-scanning guards carry a positive control or a mutation test, which deliberately breaks the protected property and requires the guard to fail by name. Without one, a guard could pass while checking nothing.

What this page does not establish

  • Oriented is not compliant. A control designed with SOC 2 in mind is not a control an auditor has tested over a period of time.
  • Tests prove code behaviour, not operations. They say nothing about how a deployment is operated: access reviews, change management, incident response, log retention and key custody all belong to your organisation and to the platform operator.
  • A compliance tag is a classification, not a finding. A rule tagged ISO42001 is a rule someone associated with that standard. Nobody has assessed it against the standard.