H.A.R.I. Deterministic Governance EN·IT Private discussion
Home/Framework/Compliance & audit
Framework / 4.1

Compliance & audit.

The platform’s compliance posture, stated truthfully. Pre-audit is pre-audit. Pilot-ready is pilot-ready. Where access has not been granted or certification has not been obtained, that is said plainly.

01 — Current status, in one place
Copyright
Registered — Brazil
Core architecture, sealed
Forensic timestamp
OpenTimestamps
ID SOV-2026-02-26
Core product
CORE_PRODUCT_SEALED
13-point stress test passed
TÜV SÜD
Pre-audit phase
Documentation complete · in progress
02

TÜV SÜD pre-audit status

The platform is in the pre-audit phase with TÜV SÜD: the documentation dossier is reviewed in advance of formal audit, scope is defined and outstanding items are surfaced. The dossier is complete; the formal audit is the next phase.

This site states that status verbatim and does not extend it. The platform is not “TÜV-certified”, not “TÜV-approved”, and carries no TÜV mark. Pre-audit is the maximum claim the relationship supports.

03

EU AI Act positioning

The platform’s architecture aligns with the Act’s intent in three load-bearing places:

TransparencyEvery decision is reproducible from inputs and policy. Satisfied structurally, not narratively.
Human oversightThe Time Sovereignty Layer makes human authority for irreversible actions architecturally required, not procedurally exhorted.
Logging & traceabilityThe hash-chained, signed forensic chain exceeds what Article 12 (record-keeping) requires for high-risk systems.

Per-vertical conformity assessment is scoped under the deployment’s use case. Where a deployment falls under Annex III high-risk classification, Articles 9, 13 and 14 are addressed by the existing architecture and documentation.

04

23-risk register

A 23-item register covering architectural, operational, integration and regulatory risk. Each item carries description, severity, likelihood, mitigating control and named responsible party. Maintained as part of the pre-audit dossier; reviewed continuously.

Full register under NDA. Categories include: chain integrity, signature key compromise, policy version drift, provider unavailability, sensor input integrity, role-token mapping leakage, replay storage durability, time-source compromise, jurisdictional shift, irreversible-action classification drift.

05

Runtime verification addendum

Continuous operational checks: chain consistency, signature validity, policy version pinning per decision, time-source health, and per-vertical invariants. The addendum is a living document; the architecture for the checks is fixed and part of the sealed core.

06

Master File / G.11 scope

The Master File compiles the architectural specification, policy framework, conformity-relevant procedures and risk register into one dossier. G.11 addresses operational governance — controls, named authorities, audit surface — the section a regulator interrogates first. Available under NDA.

08

OpenTimestamps proof

The sealed-core proof carries public ID SOV-2026-02-26, anchoring the core in a third-party-independent timeline. Verification is mechanical: the proof file verifies against the public anchor. No vendor trust required.

09

13-point stress test

Passed internally: chain consistency under load, signature integrity under partial failure, policy drift detection, time-source compromise tolerance, replay reproducibility under storage migration, irreversible-action authorization integrity, role-token reversibility refusal, provider unavailability, sensor integrity refusals, recovery-path execution, OTS anchoring durability, mass-deferral behaviour, audit replay end-to-end.

Internal. Not a third-party certification. Documented in the dossier as one input to the TÜV SÜD pre-audit.

10

What is not claimed

Not claimed

Not “TÜV-certified” or “TÜV-approved”. Not “trusted by FIFA, UEFA or any federation”. Not “certified by any third party” beyond the copyright registration in Brazil and the OpenTimestamps anchoring. Not “deployed worldwide”. No offices in any jurisdiction beyond what is true. None of those claims appear on this site, by policy.

Engagement

Full dossier under NDA.

The pre-audit dossier, risk register, Master File and per-vertical policy details are NDA-only. Public material is what you read here.