Security & trust

Security you can verify.

What’s shipped is stated as shipped. What’s in progress is stated exactly that way. No certification is claimed before it is held — being precise about the gap is how the gap gets closed.

Overview

What’s shipped is stated as shipped. What’s in progress is stated exactly that way.

11Shipped architecture properties
5Compliance regimes mapped
0Certifications claimed early
SOC 2First attestation, in progress
Pursued · Not held

No certifications are held today. Here is the order they arrive in.

The tense on this page is deliberate. When a stage completes, its status changes — nothing on this list is claimed early.

SOC 2 Type IIn progressPoint-in-time audit of control design. The first external attestation we will hold.
SOC 2 Type IIPlannedControls observed operating over a period — the report enterprise security teams actually ask for.
ISO 27001PlannedCertification of the information security management system as a whole.
ISO 42001 + ISO 27701PlannedAI management and privacy information management — certifying the regimes our modules already map.
FedRAMP ModeratePlannedThe public-sector authorization path. A multi-year effort we are sequencing deliberately.
Shipped today

Architecture properties, in plain words.

Fail-closed authenticationIf the system can’t confirm who you are, it locks you out rather than letting you in.
Encrypted, mutually-authenticated internal trafficEvery internal connection is encrypted and both ends prove who they are.
Least-privilege access, fully audit-loggedPeople only get the access their role allows, and every action is logged.
Encrypted at restStored data is encrypted, and any tampering with it is detected.
Signed registry entriesEvery model is signed, so you can tell exactly which one you’re running and that it hasn’t been swapped.
Quantum-resistant signature pathA quantum-resistant signing path is built in and available to switch on — signatures stay trustworthy even against future quantum computers.
Tamper-evident audit logThe record of what happened can’t be quietly edited — any change shows.
Content-addressed storageFiles are identified by their contents, so a changed file simply won’t load.
KMS envelope encryptionEncryption keys are managed by your own cloud’s key service, under your control.
Signed, scanned supply chainThe software ships with a verified parts list and is scanned and signed before release.
Distributed tracingYou can see exactly what the platform did, step by step, when something needs investigating.
Control mappings · Not certifications

Five regimes, mapped in the platform.

ISO/IEC 42001
AI management systems

Lifecycle governance, impact assessment, and accountability evidence mapped to the AI management standard.

NIST AI RMF 1.0
AI risk management

Govern, Map, Measure, Manage — with the generative-AI profile. Pipeline attestations supply the Measure evidence automatically.

SOC 2 TSC
Trust Services Criteria

Security, availability, and confidentiality criteria mapped to platform controls — access, change management, monitoring.

HIPAA Security Rule
Healthcare safeguards

Administrative, physical, and technical safeguard mappings for federations that touch protected health information.

EU AI Act
AI statutes

Control mappings for high-risk system obligations — documentation, logging, human oversight — as requirements phase in through 2026–2027.

Security contacts
Security
security@steav.io

Vulnerability reports, architecture questions, and security review requests.

Privacy
privacy@steav.io

Data protection questions, privacy reviews, and data subject requests.

Compliance
compliance@steav.io

Audit evidence, control mappings, and certification status inquiries.