Compliance & Audit

Compliance Is the Default,
Not a Feature Flag

Every action is attributable to a named user or service identity. Every command, code change, approval, and network call is recorded in an immutable, encrypted audit trail. Every policy decision is enforced by your administrators — not negotiated by your developers. Source code never leaves your network. Disabled employees lose access in minutes, not weeks.

Coverage at a glance

Built for the Frameworks That Govern You

Talos contributes evidence to the controls regulated organizations are measured against — banking, healthcare, government, insurance, and public companies — under one audit pipeline.

Standard
Coverage
Notes
SOC 2 (Type I & II)
Full
Common Criteria, change management, access control, monitoring, incident response.
HIPAA / HIPAA-BAA
Full
Encryption at rest and in transit, audit controls, access controls, minimum necessary.
SOX (Sarbanes-Oxley)
Full
Change authorization, segregation of duties, audit trail, IT general controls.
FedRAMP (Moderate / High)
Full
NIST 800-53 — AC, AU, CM, IR, SC, and SI control families.
GDPR
Full
Lawful basis, data minimization, right to audit, sub-five-minute revocation.
PCI-DSS 4.0
Full
Encryption, key management (HSM option), network segmentation, audit trail.
ISO 27001
Full
Information security management, access control, cryptography, operations security.
FIPS 140-2
Optional
HSM-backed signing keys for production delivery identities.
CCPA / CPRA
Full
Identity binding, retention controls, data sovereignty.
One product, your posture

The Difference Is Policy, Not Product

The same Talos binary an unregulated startup runs with audit off is the one an air-gapped federal customer runs with mandatory isolation and zero outbound connectivity. You choose the execution mode and the deployment posture; the controls travel with you.

Execution modes

Interactive

Human in the loop

Approval gates are active. A person reviews and approves at every workflow-step boundary before work proceeds.

Supervised

Human notified

The agent proceeds and a human is kept informed, with explicit approval required on destructive actions only.

Autonomous

Policy-governed

No human in the loop. Every action is logged and bounded by the configurable policy your administrators set.

Deployment postures

Full air-gap

Zero external connectivity

Reasoning runs on your own hardware. The Daedalus Knowledge Base updates through a customer-controlled offline channel. Frontier models are not used.

Approved-egress

Most regulated customers

Network egress is restricted by an admin-managed allowlist, and frontier reasoning is reached through cloud destinations you have already approved — never a Daedalus-hosted intermediary.

Open-network

Non-regulated work

Standard internet egress for development and non-production projects, with audit and identity binding still fully active.

What auditors get from us

Every Auditor Question Is a Filter and an Export

When your SOC 2, HIPAA, SOX, or FedRAMP auditor arrives, the questions they ask already have answers in the Talos compliance dashboard:

Show me every change AI made to this module last quarter.

Show me who approved this production change, when, and what tests they saw before approving.

Prove that no PHI left this network through an AI tool last year.

List every blocked network connection from any developer’s AI agent in the past six months.

Show me everything that bot identity did across all repositories.

Confirm that disabled employee X had no AI session activity after their termination date.

Show me which architectural decisions and security audits Talos performed this quarter, with their conclusions.

Export all audit records for this date range to our SIEM.