Solutions · Compliance & Audit

Regulator packs.
On demand. Signed. Offline.

Every framework mapped. Every export signed. Every question answered without a call to the vendor. The AI compliance platform and AI risk management layer for EU AI Act, SOC 2, HIPAA, and SR 11-7 audits.

32
Frameworks mapped
25 yrs
Retention window
Instant
Verify any record
Offline
Auditor never calls us
What auditors actually need

Audit is not a spreadsheet.
It’s a signed chain of custody.

Traditional audit prep
Quarter of preparation. Screenshots and Slack threads.
Subpoena
Q1
Q2
Q3

A quarter of prep. Screenshots, exported logs, Slack threads, manually reconciled spreadsheets. Every artifact is mutable and every record is one keystroke from being wrong.

Signed regulator pack
Auditor downloads. Verifies. Done.
SOC 2 Type II · FY2026
Signed Pack
sha-256: 8f3c a91d 4b2e 07c8…
Retention: 25y · Offline verify

One signed regulator pack. Cryptographic hash. Framework mapping baked in. The auditor downloads, verifies the signature offline, and closes the engagement.

“You hand them the pack. They verify. You never touch it again.”

SOC 2 · ISO 27001 · HIPAA · PCI · SR 11-7 · NYDFS · MiCA · DORA · …
How Veldt maps to Compliance & Audit

Three pillars. One auditor workspace.

Audit stops being a quarterly panic when the evidence is signed at source, the chain-of-custody is immutable, and every action is attributed to a principal. Three of Veldt’s pillars turn compliance from a scramble into a query.

01 · Evidence

Signed regulator pack, offline verification, 25-year retention

Every action lands in a hash-linked, cryptographically signed evidence chain. Retention runs 25 years. Framework mapping is baked in for SOC 2, ISO 27001, HIPAA, PCI, SR 11-7, NYDFS, MiCA, DORA: 32 frameworks total. The auditor verifies offline.

Evidence →
02 · Authority

Every action attributed for chain-of-custody

Auditors don’t care about your controls document. They care whether the specific action they’re examining can be tied to a signed principal. Every action, whether human, agent, or service account, carries an unbroken attribution chain.

Authority →
03 · Runtime Governance

Every action gated and verdict-signed at source

The evidence isn’t assembled at audit time. It’s signed at the moment of action, under 50ms. The chain records what was allowed, what was blocked, and what was escalated. The auditor sees the same record you did, when you did.

Runtime Governance →
Real scenarios

Five audits. One workflow.

SOC 2, HIPAA breach investigation, NYDFS attestation, on-site bank examination, and the internal-vs-external audit split. Every one of them collapses to the same operation: hand over the signed pack.

SOC 2 Type II
No re-explanation

SOC 2 Type II annual audit

The problem

The Type II window runs a full year. When the auditor asks about a control operating on March 14, you rebuild the story from four different tools, three ticketing systems, and the memory of an engineer who left in Q3.

With Veldt

The evidence pack covers the whole window. Every control has its signed evidence chain. When the auditor asks about March 14, you export the block, they verify the signature, and move to the next question.

Type II · weeks → days.
HIPAA breach investigation
PHI-touch chain

HIPAA breach investigation

The problem

A breach is suspected. OCR wants the PHI-touch log: which principal, which patient, which purpose. Reconstructing it from EHR audit logs and application traces takes weeks and misses the AI-agent hops entirely.

With Veldt

Every PHI touch is a signed block: principal, patient, purpose, clinician attestation. The breach-window query returns the exact chain. Retention proof is baked into the pack.

OCR ready · same day.
NYDFS 500.17
BSA/AML action chains

NYDFS 500.17 annual attestation

The problem

500.17 requires an attestation that cybersecurity and BSA/AML programs are running. The CISO signs. If the signed statement isn’t backed by an attributable action log, the attestation is a risk in itself.

With Veldt

The attestation is signed against the underlying evidence chain. Every BSA/AML action, every access review, every escalation is in the pack. The CISO signs what the chain shows.

CISO · defensible signature.
On-site examination
No live access

Bank of Anywhere on-site examination

The problem

Examiners land on-site and want a workspace. Giving them live production access is a governance nightmare. Giving them exported artifacts loses the chain-of-custody the examination is supposed to establish.

With Veldt

Examiners get an auditor workspace: a signed, offline-verifiable pack. No live system access needed. The pack answers their questions. The chain of custody survives the examination.

On-site · offline pack.
Internal vs. external
Dual-signed evidence

Internal audit vs. external auditor scope

The problem

Internal audit runs continuous. External auditors show up quarterly. The two scopes overlap and diverge, and neither trusts the other’s spreadsheet. Every audit becomes a reconciliation exercise.

With Veldt

Both sides work off the same signed chain. Internal audit exports the pack; external auditors verify the same signatures. The reconciliation exercise disappears. The chain is the source of truth.

One chain · two audiences.

Hand the auditor the pack.

Bring a real audit surface: the SOC 2 window, the HIPAA log, the NYDFS attestation. Thirty minutes: see the signed pack, offline verification, and the exact answer for the auditor’s next question.

Book a demo → Read the Evidence docs