Compliance & audit
What Kiket produces for your auditors, how optional anchor proofs work, and what frameworks we're built for.
Compliance is not a report Kiket generates about your work. Compliance is a side effect of operating inside the twin: every action that matters gets recorded, hashed, exportable, and optionally anchored in a format your auditor can verify without ever talking to us.
What gets recorded
Every:
- Case transition (from / to / actor / time / hash)
- Approval (granted / denied / comment / approver)
- Assistive suggestion (inputs / model / reasoning / acceptance)
- Config change (process edits, case-type changes, new SLAs — via the git-backed
.kiket/repo) - Scanner run and finding lifecycle (opened, triaged, remediated, resolved)
- Privileged admin action (role change, token creation, webhook registration)
...lands in an append-only event log with a cryptographic hash covering the full content.
How anchor proofs work
- Events are fingerprinted individually as they happen from a canonical representation.
- A scheduled batch job (cadence is configurable) builds a tamper-evident tree over each batch.
- The batch root can be written in a single transaction to the Polygon blockchain (low fees, EVM-compatible, public).
- The anchoring transaction ID and verification material are stored alongside the event.
Result: given any event, anyone can verify against Polygon that it existed at or before the block timestamp and hasn't been altered since — without trusting us alone. Anchoring is optional; PostgreSQL snapshots and local hash verification remain authoritative for day-to-day operations. Review and generate audit output in Audit Room.
Deep dives
Assistive AI
How model-assisted chat and hints work — drafts until recorded as evidence or case context.
Privacy & DSAR playbook
Operational playbook for privacy requests, retention, and DSAR evidence.
Audit Room
Generate audit snapshots, verify hashes, and record optional integrity proofs.
Findings & remediation
Triage scanner output, execute remediation, and close accountability loops.
Extension adapters
Evidence adapter manifests, install flow, and how extensions differ from `.kiket/` config.
Frameworks we're built for
Kiket is built for operational evidence and immutable history across common compliance programs. The platform implements controls and produces artifacts; external attestation (SOC 2 Type II, HIPAA audit, ISO 27001 certification) is separate and published to the Trust page when complete. Contact us for current status.
| Area | How Kiket helps |
|---|---|
| SOC 2 | Evidence for CC controls — access review, change management, incident response |
| HIPAA / HITECH | Breach notification processes, BAA tracking, PHI access evidence |
| SOX | Change management, segregation of duties, immutable approval history |
| GDPR | Article 30 records, DSAR handling — see Privacy & DSAR playbook |
| EU AI Act | Article 14 human oversight, assistive suggestion reasoning logs |
| 21 CFR Part 11 | Electronic signatures, audit trail, closed-system records |
| ISO 27001 | Change management, incident response, vendor review |
| KYC / AML | Customer review processes, sanctions checks, escalation |
| FOIA | Public records request handling with response SLAs |
| eDiscovery | Preservation holds, search, export packages |
Attestation status
"Built for" means the platform implements the controls and produces the artifacts. External attestation is published to the Trust page when complete. Contact us for current status.
Exporting evidence
From Audit Room or Settings → Compliance, export scoped evidence for a workspace, date range, and monitored processes:
Pick scope
Workspace, date range, monitored processes, and labels.
Pick framework lens
Choose a framework mapping (SOC 2, HIPAA, etc.). The export includes which events satisfy which control objective.
Pick format
PDF (human-readable), JSON (machine-readable), YAML (config-friendly).
Download
The file includes event data, cryptographic proof bundles, and a verify.sh script your auditor can run against Polygon when anchor proofs exist.
Data residency
- Default hosting is in the EU (specific regions are listed in order documentation and the trust page).
- Customer data never leaves the EU on the default plan.
- Enterprise customers can deploy to their own VPC or on-prem — see Self-host.
DPA + subprocessors
- Our DPA covers GDPR Article 28.
- Subprocessor list is public and maintained on the trust page.
- Customers are notified 30 days before any subprocessor change.
Responsible disclosure
Found a vulnerability? Email security@kiket.dev. We acknowledge within 24 hours and publish postmortems on the public changelog when fixes ship.