Compliance
Compliance posture
What we have, what we're working on, and what we don't yet have. We'd rather be honest about gaps than list certifications we don't hold.
The compliance value of DarkMatter resolves to three things you can prove: who made the decision, what happened, and whether the record can be trusted. Records can be verified independently, without relying on DarkMatter.
Honest disclosure: DarkMatter is an early-stage product. We do not yet hold formal third-party certifications. This page describes our current security controls and the roadmap. If your organization requires specific certifications before procurement, contact us; we can discuss timelines and what's available for Enterprise agreements.
In progress
SOC 2 Type II
We are preparing for SOC 2 Type II audit. Controls are in place. Third-party audit engagement not yet initiated. Enterprise customers can request our current controls documentation and security questionnaire responses.
Available on Enterprise
HIPAA BAA
We can discuss a Business Associate Agreement for Enterprise customers. Contact us to understand what DarkMatter can and cannot provide for healthcare workflows. DarkMatter does not store PHI by default. Payload content is controlled by the customer. BYOK encryption is available on all plans.
Implemented
GDPR
DarkMatter stores data in EU-region infrastructure where required. Data export and deletion are available on request for all accounts. No personal data is required to use the API. Agent context payloads are customer-controlled. DPA available for Enterprise.
Current security controls
Encryption
All data encrypted at rest (AES-256) and in transit (TLS 1.3). BYOK (Bring Your Own Key) available on all plans. Your key, our storage. Enterprise payloads can be client-side encrypted before commit.
Access control
API key authentication per agent. JWT session authentication for dashboard. Supabase RLS (row-level security) enforces account isolation at the database layer. Superuser access logged and auditable.
Data isolation
Every agent's commit records are isolated to the owning account via RLS. No cross-account data access is possible through the API. Self-hosting (MIT license) available for full infrastructure control.
Cryptographic integrity
Payload hashes are computed client-side before transmission. Agents sign commit envelopes with their own Ed25519 keys. Every commit receives a Merkle inclusion proof. Signed checkpoints are published to GitHub every 10 minutes. Export bundles are self-sufficient for offline verification. Use our verifier or build your own from the published spec. → Full integrity model
Subprocessors
Primary infrastructure: Railway (hosting), Supabase (database + auth), Cloudflare (DNS + CDN). Full subprocessor list available on request for Enterprise customers.
Vulnerability disclosure
Report security vulnerabilities to [email protected]. We aim to acknowledge within 24 hours and patch critical issues within 72 hours. No public bug bounty program currently.
What "independent execution record" means for compliance
The core compliance value of DarkMatter is that records are stored outside your system with cryptographic proof of integrity. This means:
→Your engineers cannot modify committed records without detection.
→An auditor can verify what your system did without trusting you to report it accurately.
→Proof bundles can be exported and verified with no ongoing DarkMatter dependency.
→The open Context Passport schema means third parties can build compatible verifiers.
This is different from formal compliance certification. "Independent execution record" describes a technical property, not a regulatory certification. For specific regulatory requirements (HIPAA, FINRA, FDA 21 CFR Part 11), contact us to discuss what DarkMatter can and cannot provide for your use case.
Contact
For security reviews, vendor questionnaires, compliance documentation, or DPA requests: [email protected]
For Enterprise procurement discussions: Enterprise page →