Compliance mappings
Mapped to the obligations you already answer to
Verillian was purpose-built for regulated work. Each framework below shows the controls Verillian is designed to support. Control-by-control mappings are available for security and procurement review.
- CJIS 6.0Criminal justice information
- Tamper-evident logging, one-year retention, fail-closed on loss of audit. Built to the policy.
- HIPAAProtected health information
- Redaction before the boundary, customer-held keys, six-year documentation retention.
- FedRAMP / FISMAFederal information systems
- Deny-by-default policy, signed policy distribution, attribute-based access control.
- CMMC 2.0 / 800-171Controlled unclassified information
- Keys on the device, localized deployment, enforcement at the moment of execution.
- FERPA / COPPAStudent records
- Sensitive-data detection and blocking before student data reaches a provider.
- GLBA / SOX / SR 11-7Financial services
- Model-activity evidence and policy enforcement across every AI tool in use.
framework support, designed by architecture · certification status available on request
Request a control-by-control mapping
We provide detailed mappings to support your security review and audit preparation.