RegTech · enterprise

Compliance isn’t bolted on. It’s generated.

Every deliberation is an immutable, attributed record by construction. Human oversight, convergence, dissent and kill-switch traces are byproducts of how Noolog runs — not paperwork assembled for an auditor afterwards. Trust like that has to hold at two layers: the protocol that runs the deliberation, and the hardware it runs on. Two pillars, one guarantee.

Pillar 01 · Protocol The deliberation proves itself

Governance, human oversight and an immutable audit trail are properties of the deliberation protocol — mapped directly onto the EU AI Act, FCA, FINRA, MAS, GDPR and SOC2.

Pillar 02 · Hardware The box proves itself

A tamper-responsive sealed enclosure with a certified integrity anchor. The record can’t be silently rewritten — because the hardware physically won’t let it.

PILLAR 01

Protocol & AI-system compliance

The software layer. Because oversight, provenance and logging are how the deliberation runs, the regulatory artifacts fall out of it — no post-hoc paperwork. Here is the full mapping, by jurisdiction.

Most enterprise AI

  • Manual logging of AI decisions after the fact
  • Third-party auditing layers bolted onto opaque models
  • Post-hoc documentation assembled for regulators
  • No native traceability from input to output

NSED architecture

  • Every agent interaction logged immutably in NATS JetStream
  • Human interventions timestamped and attributed automatically
  • Convergence and dissent recorded per deliberation round
  • Kill switch: halt a session with a full trace, instantly

Regulatory deadlines

Active nowFINRA AI Guidance
Early 2026MAS AIRM
Aug 2026EU AI Act Art. 14 / 50
2026Korea AI Basic Act

The mapping — requirement → what Noolog provides → how

Every framework below reads across three beats: the requirement it imposes, what Noolog provides against it, and how — the concrete mechanism that makes the claim real. Deadlines are in the timeline above.

Framework · requirementWhat Noolog providesHow — the mechanism
EU AI Act Art. 14
Human oversight of high-risk AI
Attributed human-in-the-loop trace, by construction.HITL trace · kill-switch · chained recordNamed operators inject / redirect / approve / reject / kill every round; each action attributed to an individual and written to the tamper-evident chain.
EU AI Act Art. 12
Transparency & record-keeping
Immutable, attributed transcript of every deliberation.Immutable chained recordNATS JetStream audit trail anchored to a Poseidon-BN254 commitment chain; per-session exportable transcript.
EU AI Act Art. 26
Log retention for deployers
Configurable, timestamp-verified retention you own.Immutable chained recordImmutable logs export to your archive; a shared chain_head makes any later edit detectable.
EU AI Act Art. 50
Content provenance (C2PA)
A signed C2PA provenance manifest per output.C2PA manifest · signed audit envelopeEach output carries models, round, operator and inputs in a DualSigner (Ed25519 + ML-DSA-65) AuditEnvelope.
FCA SM&CR
Senior-manager accountability
Named-operator audit trail at every decision point.HITL trace · kill-switchEvery decision attributed to a person; halting a session emits a full kill-switch trace.
FCA Consumer Duty
Good outcomes for consumers
Convergence and dissent captured per round.Convergence + dissent recordPer-round convergence scores and preserved dissent show how a conclusion was reached, who disagreed, and why.
FINRA AI Guidance
Model governance & supervision
Provider-agnostic, per-round model attribution.Immutable chained recordEvery model call logged with version + params to the chain; models are swappable, attribution is not.
MAS AIRM
AI risk mgmt & data sovereignty
On-prem sovereign node — nothing leaves.Region pinning · sovereign nodeAir-gapped option, jurisdiction/region pinning, zero external API dependency.
GDPR Art. 22 · PDPO
Automated-decision rights & data locality
Human-in-the-loop and on-prem locality.HITL trace · region pinning · kill-switchExplainable multi-agent chain, immediate halt on demand, and data pinned to the sovereign node.
SOC2 Type II
Security, availability, confidentiality
Immutable audit trail with role-based access.Immutable chained recordRBAC, on-prem option, and source-available code for independent review.

Your jurisdiction

🇬🇧United Kingdom

FCA SM&CR · Consumer Duty · UK GDPR · CTP

On-prem removes CTP risk. Named-operator HITL trace satisfies SM&CR accountability. Dissent logging demonstrates Consumer-Duty good outcomes.

🇪🇺European Union

EU AI Act · GDPR Art. 22 · DORA

Art. 14 oversight is the core architecture; Art. 12 logging is a byproduct; Art. 50 provenance per output; kill switch = emergency stop.

🇺🇸United States

FINRA · SEC AI · SOC2 · State AI

Per-round model attribution satisfies FINRA governance. SOC2-ready trail. Source-available enables independent review for federal procurement.

🇸🇬Singapore

MAS AIRM · PDPA · MAS TRM

Air-gapped on-prem for full data sovereignty. Zero external API satisfies MAS outsourcing. Configurable retention for PDPA.

🇰🇷South Korea

AI Basic Act · PIPA · FSC

Kill switch + HITL override meet the AI Basic Act’s high-risk requirements. On-prem for PIPA data localization. Trail for FSC reporting.

🇭🇰Hong Kong

HKMA · SFC · PDPO

HKMA expects explainability + human oversight in banking — the transcript and HITL trace provide both. On-prem for PDPO localization.

Compliance artifacts — generated, not assembled

ARTIFACT_01Deliberation transcript

Complete agent conversation across all rounds — every prompt, response and reasoning step, timestamped.

ARTIFACT_02Convergence report

Agreement heatmaps, per-round convergence scores, final consensus metrics — exactly how agents aligned or diverged.

ARTIFACT_03HITL injection log

Every human intervention timestamped and attributed — injections, redirections, approvals, rejections — to named operators.

ARTIFACT_04Dissent record

Which agents disagreed, on what, and why — preserved even when consensus is reached. Critical for FCA Consumer Duty.

ARTIFACT_05Kill-switch trace

On halt: a full state snapshot — partial results, active agents, reason for termination, operator identity. Art. 14 & SM&CR ready.

Sample export — a real generated report

Not a mockup. This is the C2PA provenance manifest Noolog writes for a finished deliberation — carrying verbatim field names and the real claim-ledger tally. The same report renderer also produces IEC 62304 and FDA algorithm-record documents.

Generated report · header Raise prices 10%?
winnerEngineerBot
answerShip with grandfathering.
rounds3
convergence92%
evaluator agreement78%
chain_heada3dbbad…
generated_at2026-08-01T00:00:00Z
verified 5 contested 1 wrong 0 unverified 2

Emitted live to NATS nsed.{session}.audit.* as a signed AuditEnvelope — DualSigner: Ed25519 + ML-DSA-65 (post-quantum) — and anchored to a Poseidon-BN254 commitment chain. The same chain_head rides every event of the deliberation. Tamper-evident by construction.

Where the report is going

Roadmap · designed, not shipped

Regulatory Traceability Mode

Today's export is tamper-evident and machine-readable. Next it becomes regulator-ready and independently verifiable. This is on our roadmap — a designed premium-enterprise direction shown here as intent, not a shipped feature.

traceabilityTraceability matrix

Requirement → proposal → PM approval → QA evaluation → QA-lead sign-off, each row cryptographically signed. Export as JSON, CSV, or a PDF regulators can ingest.

templatesRegulatory template library

One deliberation, rendered into IEC 62304, DO-178C and 21 CFR Part 11 submission formats.

verificationEnd-to-end signature verification

The DualSigner envelopes are emitted today; a recipient-side verifier turns "tamper-evident" into "independently verifiable — any post-export edit is detectable."

evidence packSigned evidence pack

Verdict, dissents, per-string provenance and explicit liability mapping bundled with a replayable, chained audit trail.

Frontend — open-source Slint

Compliance isn't only the protocol and the box. The interface an operator actually touches is built in open-source Slint — a statically-typed UI toolkit that compiles to native Rust/C++ with no garbage-collected runtime and deterministic execution, shipped with a GUI test-automation framework. That engineering discipline is exactly what lets a safety-critical UI be certified — so the interface is built to map onto the major functional-safety and software-quality frameworks.

Medical IEC 62304 · ISO 14971
RequirementSoftware lifecycle & clinical risk management.
Noolog providesEngineered-to-bar operator UI + a full audit trail.
HowOpen-source Slint discipline — deterministic, no GC — writing every action to the append-only chained record.
Automotive · Aerospace ISO 26262 · DO-178C
RequirementSafety / non-safety segregation, no hidden runtime.
Noolog providesA UI that compiles to native, statically-typed code.
HowSlint compiles to native Rust/C++ with deterministic execution — no garbage-collected runtime to reason about.
Industrial · Rail IEC 61508 · EN 50128 / 50657
RequirementFunctional safety with deterministic bounds.
Noolog providesA low-resource UI with bounded, predictable execution.
HowBare-metal-capable toolkit with a GUI test-automation framework, built and tested for exactly these regimes.
Straight talk

Not every standard applies to every deployment — several are embedded- or hardware-specific. The point isn't that the desktop app is certified to all of them; it's that the UI is engineered to that bar, on a toolkit built and tested for exactly these regimes.

PILLAR 02

Hardware compliance

A protocol is only as trustworthy as the machine underneath it. So the second pillar moves the guarantee into silicon: the device is a sealed, tamper-responsive enclosure whose on-board integrity anchor makes the audit trail append-only and tamper-evident. The log can’t be quietly rewritten — the hardware physically resists it.

The casing is the encryption boundary

Everything that touches your data — SSD, NPU, TPM, and an optional HSM — lives inside one sealed boundary. Integrity is anchored in one of two ways: an HSM that owns an append-only tamper log, or internal buses hardened so nothing can sit between the components undetected.

Two ways to anchor integrity

Path A · HSM-anchored Certify the HSM

An on-device Hardware Security Module owns an append-only, tamper-evident log. We target certifying it to a recognised standard so the tamper-log guarantee is independently verifiable, not just asserted.

OR
Path B · HSM-omitted Harden the buses

Drop the HSM if every internal path — SSD ↔ NPU ↔ TPM — is secured against man-in-the-middle by physical design, using the IDE (Integrity & Data Encryption) and SPDM protocols end to end.

Straight talk

Chasing full standard certification is, in part, a marketing move — a badge buyers and regulators recognise. We say so plainly. But the reason it’s worth doing is that the standard forces the integrity to be real and independently checkable, not a claim in a datasheet.

Certification targets

Tamper resistance EN ISO/IEC 19790 Level 4 or GM/T 0028-2024
RequirementActive response to physical intrusion, highest tier.
Noolog providesAn HSM that owns an append-only, tamper-evident log.
HowCertifying the HSM to the standard makes the tamper-log guarantee independently verifiable, not just asserted.
Ingress protection IP55
RequirementRated against dust and low-pressure water jets.
Noolog providesA sealed encryption boundary rated for real-world deployment.
HowSSD, NPU, TPM and optional HSM all live inside one sealed casing — the boundary that keeps data enclosed.
Enclosure Tamper-responsive · filtered RF feedthrough
RequirementThe physical seal stays intact end to end.
Noolog providesA tamper-responsive casing that is the encryption boundary.
HowThe external antenna passes through a filtered RF feedthrough, and internal buses are hardened with IDE + SPDM.
Request enterprise access →