Compliance Controls
Governance is designed into the storage layer, enforced on every request by policy, with a signed record. The controls regulators and security reviewers ask about are how IronShard works, not a layer added on top. This page describes what those controls are, which of them are available today, and what they give you as evidence. The provider-independent privacy model is covered in GDPR Everywhere; certifications, providers, and legal documents are on the Trust Center.
Status
| Control | Status |
|---|---|
| Encryption, erasure coding, and distribution across providers | Available |
| Residency through geo-fencing | Available |
| Per-agent access control | In development |
| Signed audit log | In development |
| Lineage and reproducibility | In development |
| Isolated branches of production | In development |
The controls
Residency is yours to set. Data is pinned to the jurisdictions you choose through geo-fences. Because providers hold only encrypted fragments, the compliance posture of any single provider or region does not determine yours, and multi-cloud, hybrid, and cross-border setups stay within the residency boundaries you define.
Access is scoped and enforced per agent. In development. Every agent and user gets its own credentials, scoped per bucket, prefix, or key, with optional IP and time-window restrictions. Every request is policy-checked at the storage layer before data is served, and denials are recorded alongside approvals.
Every action is on record, signed. In development. Reads, writes, merges, and policy decisions land in an immutable, cryptographically signed audit log. Records cannot be edited, deleted, or backdated. The log is searchable and exportable, and agents can query it over MCP. See Log
Lineage and reproducibility are automatic. In development. Snapshots and branches record which data state each run used. Which dataset trained which model, and what a given run read and wrote, is answerable from the record rather than reconstructed afterward. See Branching and Snapshots
Production is isolated from experimentation. In development. Agents work on isolated, copy-on-write branches of production, one per task. Nothing reaches production without passing review, whether that review is a policy check or a human sign-off. See Branch
How this maps to regulation
IronShard does not certify your workloads, and no storage layer can. What it does is make the controls above defaults, so the evidence a framework asks for already exists.
- GDPR: the provider-independent privacy model, plus encryption everywhere, residency controls, scoped access, and a complete access record.
- EU AI Act: documented data lineage, reproducibility, and immutable audit trails for training and inference data, the record the Act's transparency and accountability requirements depend on.
- Sector frameworks (HIPAA, GLBA, PCI-DSS, ISO 27001, SOC 2): IronShard is engineered to meet the storage-layer requirements these frameworks share: encryption, least-privilege access, tamper-evident logging, and residency. Underlying storage providers operate data centers certified to ISO 27001, SOC 2, and PCI-DSS; certifications on your own workloads remain your responsibility, and IronShard's evidence is built to support them.
