Compliance frameworks
Compliance frameworks
Frameworks · v2026.06: How Foundry’s controls map to the standards we operate against.
HIPAA governs PHI we handle as a business associate. CCPA/CPRA governs personal information of California consumers (PHI is excluded by the HIPAA carve-out). Our policy library is structured around ISO/IEC 27001:2022 and ISO/IEC 42001:2023, and Foundry’s controls are mapped to the SOC 2 Trust Services Criteria. The framework crosswalk below is the consolidated, multi-framework view that Foundry policies are mapped against.
Start here
Per-framework deep dives
Administrative, physical, and technical safeguards, mapped to Foundry policies and the business-associate boundary.
Annex A controls mapped to Foundry policies, with status (in place / planned / not applicable) for each.
How our AI governance, lifecycle, and oversight map to the AIMS standard for Atlas and Forge Agents.
The platform review completed Feb 2026 and how findings are tracked to remediation.
Authenticator assurance levels, MFA posture, and the SMS-disallowed rule.