[{"data":1,"prerenderedAt":381},["ShallowReactive",2],{"docs-meta-/docs/compliance-controls":3,"content-query-8oHOBBWtqo":6,"markdown-page-nav:{\"path\":\"/docs\"}":327,"content-navigation-Tlu2f2EPlD":368},{"title":4,"description":5},"Compliance Controls","The storage-layer controls behind IronShard's compliance posture, which of them are available today, and how they map to GDPR, the EU AI Act, and sector frameworks.",{"_path":7,"_dir":8,"_draft":9,"_partial":9,"_locale":10,"title":4,"description":5,"navigation":11,"body":14,"_type":321,"_id":322,"_source":323,"_file":324,"_stem":325,"_extension":326},"/docs/compliance-controls","docs",false,"",{"group":12,"order":13},"Compliance",10,{"type":15,"children":16,"toc":315},"root",[17,25,48,55,156,162,181,199,220,241,262,268,273],{"type":18,"tag":19,"props":20,"children":22},"element","h1",{"id":21},"compliance-controls",[23],{"type":24,"value":4},"text",{"type":18,"tag":26,"props":27,"children":28},"p",{},[29,31,38,40,46],{"type":24,"value":30},"Governance is designed into the storage layer, enforced on every request by policy, with a signed record. The controls regulators and security reviewers ask about are how IronShard works, not a layer added on top. This page describes what those controls are, which of them are available today, and what they give you as evidence. The provider-independent privacy model is covered in ",{"type":18,"tag":32,"props":33,"children":35},"a",{"href":34},"/docs/gdpr-everywhere",[36],{"type":24,"value":37},"GDPR Everywhere",{"type":24,"value":39},"; certifications, providers, and legal documents are on the ",{"type":18,"tag":32,"props":41,"children":43},{"href":42},"/trust-center",[44],{"type":24,"value":45},"Trust Center",{"type":24,"value":47},".",{"type":18,"tag":49,"props":50,"children":52},"h2",{"id":51},"status",[53],{"type":24,"value":54},"Status",{"type":18,"tag":56,"props":57,"children":58},"table",{},[59,77],{"type":18,"tag":60,"props":61,"children":62},"thead",{},[63],{"type":18,"tag":64,"props":65,"children":66},"tr",{},[67,73],{"type":18,"tag":68,"props":69,"children":70},"th",{},[71],{"type":24,"value":72},"Control",{"type":18,"tag":68,"props":74,"children":75},{},[76],{"type":24,"value":54},{"type":18,"tag":78,"props":79,"children":80},"tbody",{},[81,95,107,120,132,144],{"type":18,"tag":64,"props":82,"children":83},{},[84,90],{"type":18,"tag":85,"props":86,"children":87},"td",{},[88],{"type":24,"value":89},"Encryption, erasure coding, and distribution across providers",{"type":18,"tag":85,"props":91,"children":92},{},[93],{"type":24,"value":94},"Available",{"type":18,"tag":64,"props":96,"children":97},{},[98,103],{"type":18,"tag":85,"props":99,"children":100},{},[101],{"type":24,"value":102},"Residency through geo-fencing",{"type":18,"tag":85,"props":104,"children":105},{},[106],{"type":24,"value":94},{"type":18,"tag":64,"props":108,"children":109},{},[110,115],{"type":18,"tag":85,"props":111,"children":112},{},[113],{"type":24,"value":114},"Per-agent access control",{"type":18,"tag":85,"props":116,"children":117},{},[118],{"type":24,"value":119},"In development",{"type":18,"tag":64,"props":121,"children":122},{},[123,128],{"type":18,"tag":85,"props":124,"children":125},{},[126],{"type":24,"value":127},"Signed audit log",{"type":18,"tag":85,"props":129,"children":130},{},[131],{"type":24,"value":119},{"type":18,"tag":64,"props":133,"children":134},{},[135,140],{"type":18,"tag":85,"props":136,"children":137},{},[138],{"type":24,"value":139},"Lineage and reproducibility",{"type":18,"tag":85,"props":141,"children":142},{},[143],{"type":24,"value":119},{"type":18,"tag":64,"props":145,"children":146},{},[147,152],{"type":18,"tag":85,"props":148,"children":149},{},[150],{"type":24,"value":151},"Isolated branches of production",{"type":18,"tag":85,"props":153,"children":154},{},[155],{"type":24,"value":119},{"type":18,"tag":49,"props":157,"children":159},{"id":158},"the-controls",[160],{"type":24,"value":161},"The controls",{"type":18,"tag":26,"props":163,"children":164},{},[165,171,173,179],{"type":18,"tag":166,"props":167,"children":168},"strong",{},[169],{"type":24,"value":170},"Residency is yours to set.",{"type":24,"value":172}," Data is pinned to the jurisdictions you choose through ",{"type":18,"tag":32,"props":174,"children":176},{"href":175},"/docs/resilience#geo-fencing",[177],{"type":24,"value":178},"geo-fences",{"type":24,"value":180},". Because providers hold only encrypted fragments, the compliance posture of any single provider or region does not determine yours, and multi-cloud, hybrid, and cross-border setups stay within the residency boundaries you define.",{"type":18,"tag":26,"props":182,"children":183},{},[184,189,191,197],{"type":18,"tag":166,"props":185,"children":186},{},[187],{"type":24,"value":188},"Access is scoped and enforced per agent.",{"type":24,"value":190}," ",{"type":18,"tag":192,"props":193,"children":194},"em",{},[195],{"type":24,"value":196},"In development.",{"type":24,"value":198}," Every agent and user gets its own credentials, scoped per bucket, prefix, or key, with optional IP and time-window restrictions. Every request is policy-checked at the storage layer before data is served, and denials are recorded alongside approvals.",{"type":18,"tag":26,"props":200,"children":201},{},[202,207,208,212,214],{"type":18,"tag":166,"props":203,"children":204},{},[205],{"type":24,"value":206},"Every action is on record, signed.",{"type":24,"value":190},{"type":18,"tag":192,"props":209,"children":210},{},[211],{"type":24,"value":196},{"type":24,"value":213}," Reads, writes, merges, and policy decisions land in an immutable, cryptographically signed audit log. Records cannot be edited, deleted, or backdated. The log is searchable and exportable, and agents can query it over MCP. ",{"type":18,"tag":32,"props":215,"children":217},{"href":216},"/log",[218],{"type":24,"value":219},"See Log",{"type":18,"tag":26,"props":221,"children":222},{},[223,228,229,233,235],{"type":18,"tag":166,"props":224,"children":225},{},[226],{"type":24,"value":227},"Lineage and reproducibility are automatic.",{"type":24,"value":190},{"type":18,"tag":192,"props":230,"children":231},{},[232],{"type":24,"value":196},{"type":24,"value":234}," Snapshots and branches record which data state each run used. Which dataset trained which model, and what a given run read and wrote, is answerable from the record rather than reconstructed afterward. ",{"type":18,"tag":32,"props":236,"children":238},{"href":237},"/docs/branching",[239],{"type":24,"value":240},"See Branching and Snapshots",{"type":18,"tag":26,"props":242,"children":243},{},[244,249,250,254,256],{"type":18,"tag":166,"props":245,"children":246},{},[247],{"type":24,"value":248},"Production is isolated from experimentation.",{"type":24,"value":190},{"type":18,"tag":192,"props":251,"children":252},{},[253],{"type":24,"value":196},{"type":24,"value":255}," Agents work on isolated, copy-on-write branches of production, one per task. Nothing reaches production without passing review, whether that review is a policy check or a human sign-off. ",{"type":18,"tag":32,"props":257,"children":259},{"href":258},"/branch",[260],{"type":24,"value":261},"See Branch",{"type":18,"tag":49,"props":263,"children":265},{"id":264},"how-this-maps-to-regulation",[266],{"type":24,"value":267},"How this maps to regulation",{"type":18,"tag":26,"props":269,"children":270},{},[271],{"type":24,"value":272},"IronShard does not certify your workloads, and no storage layer can. What it does is make the controls above defaults, so the evidence a framework asks for already exists.",{"type":18,"tag":274,"props":275,"children":276},"ul",{},[277,295,305],{"type":18,"tag":278,"props":279,"children":280},"li",{},[281,286,288,293],{"type":18,"tag":166,"props":282,"children":283},{},[284],{"type":24,"value":285},"GDPR:",{"type":24,"value":287}," the ",{"type":18,"tag":32,"props":289,"children":290},{"href":34},[291],{"type":24,"value":292},"provider-independent privacy model",{"type":24,"value":294},", plus encryption everywhere, residency controls, scoped access, and a complete access record.",{"type":18,"tag":278,"props":296,"children":297},{},[298,303],{"type":18,"tag":166,"props":299,"children":300},{},[301],{"type":24,"value":302},"EU AI Act:",{"type":24,"value":304}," documented data lineage, reproducibility, and immutable audit trails for training and inference data, the record the Act's transparency and accountability requirements depend on.",{"type":18,"tag":278,"props":306,"children":307},{},[308,313],{"type":18,"tag":166,"props":309,"children":310},{},[311],{"type":24,"value":312},"Sector frameworks (HIPAA, GLBA, PCI-DSS, ISO 27001, SOC 2):",{"type":24,"value":314}," IronShard is engineered to meet the storage-layer requirements these frameworks share: encryption, least-privilege access, tamper-evident logging, and residency. Underlying storage providers operate data centers certified to ISO 27001, SOC 2, and PCI-DSS; certifications on your own workloads remain your responsibility, and IronShard's evidence is built to support them.",{"title":10,"searchDepth":316,"depth":316,"links":317},2,[318,319,320],{"id":51,"depth":316,"text":54},{"id":158,"depth":316,"text":161},{"id":264,"depth":316,"text":267},"markdown","content:docs:compliance-controls.md","content","docs/compliance-controls.md","docs/compliance-controls","md",[328],{"title":329,"_path":330,"children":331},"Docs overview","/docs",[332,337,341,345,346,350,352,356,360,364],{"title":333,"_path":334,"group":335,"order":336},"Adaptive Storage Representation","/docs/adaptive-storage","Platform",7,{"title":338,"_path":339,"group":340,"order":316},"Agent Buckets","/docs/agent-buckets","Get Started",{"title":342,"_path":237,"group":343,"order":344},"Branching and Snapshots","Features",8,{"title":4,"_path":7,"group":12,"order":13},{"title":347,"_path":348,"group":340,"order":349},"Connect Claude over MCP","/docs/connect-claude",1,{"title":37,"_path":34,"group":12,"order":351},9,{"title":353,"_path":354,"group":335,"order":355},"Secure Ingest Pipeline","/docs/ingest-pipeline",5,{"title":357,"_path":358,"group":335,"order":359},"Erasure Coding and Distribution","/docs/resilience",6,{"title":361,"_path":362,"group":340,"order":363},"Get Started with the S3 API","/docs/s3-quickstart",3,{"title":365,"_path":366,"group":335,"order":367},"System Architecture","/docs/system-architecture",4,[369],{"title":329,"_path":330,"children":370},[371,372,373,374,375,376,377,378,379,380],{"title":333,"_path":334,"group":335,"order":336},{"title":338,"_path":339,"group":340,"order":316},{"title":342,"_path":237,"group":343,"order":344},{"title":4,"_path":7,"group":12,"order":13},{"title":347,"_path":348,"group":340,"order":349},{"title":37,"_path":34,"group":12,"order":351},{"title":353,"_path":354,"group":335,"order":355},{"title":357,"_path":358,"group":335,"order":359},{"title":361,"_path":362,"group":340,"order":363},{"title":365,"_path":366,"group":335,"order":367},1791472366453]