SCBE AETHERMOORE
Compliance

Map your AI governance to the frameworks that matter.

SCBE-AETHERMOORE aligns with 9 major compliance frameworks. The pump generates audit logs automatically — compliance documentation that writes itself.

Strong alignment

EU AI Act (Aug 2026)

Risk management, data governance, technical documentation, automatic logging, transparency, and human oversight. The pump handles AI-specific controls for high-risk systems.

Strong alignment

NIST AI RMF 1.0

Map, Measure, Manage, Govern. The 14-layer pipeline provides measurement (L1-L12), governance decisions (L13), and audit telemetry (L14) across all four functions.

Strong alignment

MITRE ATLAS

91/91 ATLAS-mapped attacks blocked in benchmarking. Trichromatic governance catches evasion, reconnaissance, and model abuse techniques.

Strong alignment

NIST FIPS 203/204 (PQC)

ML-KEM-768 (FIPS 203) for key encapsulation, ML-DSA-65 (FIPS 204) for digital signatures. Quantum-resistant from day one. 100% crypto test pass rate.

Mapped

SOC 2 Type II

JSONL audit logs for every governance decision. Immutable timestamps, tongue profiles, and source references. Export directly to your auditor.

Mapped

CMMC Level 2+

PQC crypto, access controls, audit logging, and airgap-capable deployment. Designed for classified environments and defense contractor requirements.

Mapped

HIPAA

Access controls, audit trails, encryption (AES-256-GCM), and governance decisions logged per query. Domain separation prevents medical AI from drifting into unauthorized areas.

Mapped

ISO 42001

AI management system standard. The pump provides continuous monitoring, risk assessment (L13 decisions), and documented governance policies.

Reference

OWASP LLM Top 10

Prompt injection (#1), insecure output handling (#2), training data poisoning (#3), model denial of service (#4), supply chain (#5) — all addressed by the 14-layer pipeline.

EU AI Act Compliance Matrix

Effective August 2026. These are the Article 9-15 requirements for high-risk AI systems and how SCBE addresses each.

RequirementArticleSCBE CoverageStatus
Risk management systemArt. 914-layer pipeline with L13 ALLOW/QUARANTINE/ESCALATE/DENY decisionsCovered
Data governanceArt. 10Label consolidation pipeline, tongue profiling for domain separation, deduplicationCovered
Technical documentationArt. 11Automatic JSONL audit logs, governance decision records, tongue profilesCovered
Record-keepingArt. 12Immutable audit trail with timestamps, decision rationale, and source referencesCovered
TransparencyArt. 13Governance decisions are explainable — tongue profile + null pattern + distance metricCovered
Human oversightArt. 14QUARANTINE/ESCALATE tiers require human review before executionCovered
Accuracy & robustnessArt. 1585.7% detection at 0% FP, 91/91 attacks blocked, property-based testing (L4)Covered
CybersecurityArt. 15(4)ML-KEM-768 + ML-DSA-65 + AES-256-GCM. Post-quantum resistant. 0 CVEs.Covered

NIST AI Risk Management Framework

FunctionSCBE MappingPipeline Layers
GOVERNGovernance gate decisions, policy enforcement, Sacred Tongues domain separationL13, L12
MAPContext realification, Poincare embedding, multi-well Hamiltonian modelingL1-L4, L8
MEASUREHyperbolic distance, spectral coherence, triadic temporal distance, harmonic wallL5, L9-L12
MANAGERisk tier assignment, audit telemetry, cascade injection detectionL13-L14

OWASP LLM Top 10 Coverage

VulnerabilityOWASP #SCBE DefenseStatus
Prompt InjectionLLM01Tongue profiling detects narrow activation patterns; null-space absence detection catches injections that leave 4-5 domains silentCovered
Insecure Output HandlingLLM02Output verification via second pump pass; tongue profile of output must match expected domainCovered
Training Data PoisoningLLM03Label consolidation, deduplication, governance scanning on all training data ingestionCovered
Model Denial of ServiceLLM04Rate limiting, hyperbolic cost scaling makes resource exhaustion attacks exponentially expensiveCovered
Supply ChainLLM05PQC signatures on all artifacts, provenance tracking, weekly security auditsCovered
Sensitive Information DisclosureLLM06Domain separation via Sacred Tongues prevents cross-domain data leakageCovered
Insecure Plugin DesignLLM07Governance gate validates all agent-to-agent communications; MCP server enforces scopeCovered
Excessive AgencyLLM08QUARANTINE/DENY tiers block autonomous actions outside approved scopeCovered
OverrelianceLLM09Confidence scoring, domain drift detection, ESCALATE tier for uncertain decisionsPartial
Model TheftLLM10PQC encryption on model artifacts, ML-DSA-65 signatures, access loggingCovered

What the Audit Log Contains

Every query through the pump generates a JSONL record with:

{
  "timestamp": "2026-04-01T13:45:22.107Z",
  "query_hash": "sha256:a1b2c3...",
  "tongue_profile": { "KO": 0.82, "AV": 0.41, "RU": 0.15, "CA": 0.03, "UM": 0.01, "DR": 0.00 },
  "null_pattern": ["CA", "UM", "DR"],
  "hyperbolic_distance": 0.342,
  "harmonic_cost": 1.127,
  "governance_decision": "ALLOW",
  "confidence": 0.94,
  "processing_ms": 7.2,
  "source_ip_hash": "sha256:d4e5f6...",
  "model_id": "gpt-4o",
  "session_id": "sess_abc123"
}

Export as JSONL, CSV, or pipe directly to your SIEM. Compatible with Splunk, Datadog, ELK, and any log aggregator.

Need compliance documentation for your AI deployment?

The pump generates audit trails automatically. No security hire needed. EU AI Act deadline is August 2026.