Technical Documentation & Architecture Specs
EU AI Act Article 11: Technical Documentation Requirements
- Control objective
- Maintain comprehensive, verifiable documentation detailing system architecture, capabilities, and data provenance.
- How the session record supports it
- Capability manifests declare permissions, event families, and trust levels. Regulated evidence bundles bind reviewed artifact digests.
- Evidence artifact
- Compliance Evidence Pack / Capability Manifests
- Audit chapter
- Surface & Capabilities
- Suggested reviewer
- VP of Software Engineering
- Reference in code
- docs/compliance-evidence-pack.md
Automated Tamper-Evident Event Logging
EU AI Act Article 12: Automatic Record-Keeping of Operations
- Control objective
- Automatically capture complete, immutable logs of all agent tool calls, model inferences, inputs, and outcomes throughout operations.
- How the session record supports it
- The event ledger stores signed agent_activity.v1 records. Evidence export and provenance rows use append-only hash chains.
- Evidence artifact
- agent_activity.v1 Ledger / Append-Only Export Chain
- Audit chapter
- Audit Ledger & Chains
- Suggested reviewer
- Chief Information Security Officer (CISO)
- Reference in code
- app/api/verification-portal/ingest/route.ts
Human-in-the-Loop Oversight & Rationales
EU AI Act Article 14: Human Oversight & Interventions
- Control objective
- Enable effective human intervention to gate, inspect, approve, or halt autonomous actions with documented reviewer rationale.
- How the session record supports it
- Runtime sensitivity can hold specified tool calls. The approval ledger records reviewer decisions and available rationale.
- Evidence artifact
- Approval Decision Records / Deviations Review Queue
- Audit chapter
- Human Decisions & Rationale
- Suggested reviewer
- Head of Model Risk (MRM)
- Reference in code
- app/verification-portal/approvals/page.tsx
Cybersecurity & Data Redaction Defense
EU AI Act Article 15: Accuracy, Robustness, and Cybersecurity
- Control objective
- Protect against sensitive data leakage, credential poisoning, and unredacted customer data passing into LLM telemetry.
- How the session record supports it
- Deterministic regex catalog (AWS, GitHub, JWT, Stripe keys) + Shannon entropy fallback scrubs credentials before payload emission.
- Evidence artifact
- Redact-Before-Emit Summary / Manifest Redaction Policy
- Audit chapter
- Redaction & Security
- Suggested reviewer
- Data Protection Officer (DPO)
- Reference in code
- packages/verifier-portal-client/src/secret-redactor.ts