Compliance posture
LSAS is designed to help security, compliance, and platform teams implement the technical enforcement and observability they need for existing governance programs. It does not create compliance on its own; instead it provides the evidence and controls hooks your programs rely on.
The runtime is intended to align with the kinds of controls found in SOC 2 and ISO 27001 programs, HIPAA/PHI safeguards, and PCI-like patterns for financial data – without making any promise of certifications. You map LSAS signals and workflows into your own policy stack.
Override capability status
Governed overrides are now available in the Sandbox with structured request fields, policy-constrained outcomes, explicit execution confirmation, and audit telemetry capture. Override execution events are visible in homepage telemetry and tenant-console audit views.
Current scope is sandbox and governance validation workflows; runtime-wide production override APIs across all LSAS routes are not yet generally available.
Healthcare connector boundary status
LSAS now includes Epic-backed sandbox connector-boundary flows that govern ingress and egress around FHIR/OAuth traffic. This demonstrates application-layer controls around a system-of-record boundary, including governed release behavior and runtime evidence capture.
Current scope is sandbox-backed execution for search/read flows and telemetry validation. It is not a claim of universal workflow coverage or broad production certification.
Auditability & evidence
- Per-request event trail including tenant, app, environment, and risk domains.
- Deterministic decision records with tiers, rule hits, and remediation actions.
- Connector-boundary timeline records for governed healthcare ingress/egress execution paths.
- Versioned policy packs so every decision can be tied to a specific configuration.
- Change history suitable for linking into your existing ticketing and CAB process.
Controls mapping (without promises)
LSAS exposes building blocks that can be mapped into your control framework. It is not a certification or a shortcut to compliance; it simply makes technical enforcement and observability easier to reason about.
- SOC 2 and ISO 27001: logging, access control integration, and change tracking.
- HIPAA/PHI: derived-only telemetry and minimum-necessary visibility for regulators.
- PCI-like patterns: detectors and policies for card data and secrets in prompts.
Least privilege & data minimization
- Role-scoped views in the console so teams only see what they need.
- Derived-only telemetry by default; raw prompts/completions can be disabled entirely.
- Optional redaction of PHI/PII, secrets, and PCI-like patterns before storage.
- Segmentation by tenant, app, and environment for clean blast-radius boundaries.
Deployment and residency
- Private deployment by default: private single-tenant, customer-hosted cloud/VPC, or self-hosted/on-prem.
- Managed sandbox evaluation is available for controlled pre-production validation.
- Data residency aligned to where you deploy your database and logging stack.
- Encryption at rest and in transit implemented using your cloud provider primitives.
- Retention windows enforced through your database and logging configuration, aligned with your policies.
Operational hooks
- Structured decision telemetry and extension points you can wire into webhooks or message sinks for incident management and SIEM.
- Explicit decision state for HITL escalation, plus schemas for cases, approvals, and attestations with rich context.
- Signals that can be correlated with upstream application and model logs.
- A telemetry model that supports dry-run and replay tooling when you choose to build it.
- Tenant mutation audit events for onboarding, membership, policy-assignment, and API key lifecycle actions.
- Conflict-safe API key revoke semantics with explicit 409 responses and audit evidence when stale admin state is detected.
How this relates to other pages
Compliance posture is one slice of your overall governance story. You can combine this page with deeper views on security and privacy when preparing materials for procurement or internal review.
Next steps
Evaluate LSAS in your environment
Flexible deployment for regulated teams: managed evaluation sandbox, private single-tenant deployment, customer-hosted cloud/VPC deployment, or self-hosted/on-prem rollout.
- Customer-hosted by default
- Policy packs per app and tenant
- Audit-ready telemetry out of the box
Guided evaluations and design partner programs are available for teams operating under SOC 2, ISO 27001, HIPAA, and similar frameworks.