Platform and trust

Trust you can inspect, not a score you must believe.

A CISO, an auditor, and a policy owner all ask the same question in different words: why should I believe this system? EKOS answers in inspectable mechanisms, not adjectives.

Trust mechanisms

Source citations and provenance

Important AI-assisted artifacts retain their source document and version, the supporting passage, confidence, extraction method, model identity, timestamp, and review state. Search results and Ask citations lead back to source material, graph edges expose evidence from both sides, and review decisions stay attached to the artifact they governed.

Local classification and controlled model routing

During ingestion, EKOS locally detects configured sensitive-data patterns and assigns document and passage sensitivity. Content can be allowed, redacted, or blocked before ingestion-time external model calls, with deterministic placeholders preserving useful structure while the authorized text stays in the tenant's stored, searchable record. Local model slots support on-boundary embedding and generation paths.

Tenant and organization segmentation

Verified identity establishes tenant and actor context; caller-supplied identity is never trusted. Server-side queries scope reads to the caller's tenant, permitted organizations, and subscribed corpora across Search, Ask, documents, the graph, and MCP. Tenant-prefixed object storage and tenant-bound service credentials reinforce the same boundary.

Version history and stale evidence

Uploads and connector changes converge on one idempotent, version-first pipeline. Source bytes are stored before processing, duplicates collapse, and changed documents create new versions instead of overwrites. Only the current version serves retrieval, while retained history powers diffs, provenance, and the staleness marks that keep old proof from quietly standing in for new obligations.

Tamper-evident audit history

Sensitive reads, decisions, and administrative actions create audit events. Events are individually hashed and can be sealed into tenant-specific chained batches. Administrators verify event hashes, batch digests, and seal continuity, then export sealed events with their proof context, so a silent change to covered history is detectable.

No single score

Five distinct states, instead of one number.

A single blended figure hides exactly the things an examiner will ask about. EKOS keeps the states separate, each with its own evidence behind it.

Coverage

Which requirements have reviewed or policy-accepted mappings, requirement by requirement.

Gaps

Requirements with no qualifying mapping, shown as work to do rather than hidden in an average.

Review state

Whether a person has approved, rejected, or still owes a decision on a proposed relationship.

Evidence freshness

Whether proof still cites current text, or went stale when the language it supported changed.

Change status

Where each regulatory or document change sits in its classification and response lifecycle.

The honest boundary

What EKOS deliberately does not claim.

EKOS provides governed workflows, reviewed mappings, traceable decisions, and verifiable evidence artifacts. It supports deployment-specific compliance programs run by your organization.

  • It does not determine legal applicability of any rule to your organization.
  • It does not certify an organization or control against any framework.
  • It does not guarantee a compliance outcome, in any deployment.
  • Evidence-package verification shows internal consistency of the record, not the sufficiency or truth of the underlying evidence.

Documented coverage, explicit gaps, review history, and verifiable artifacts make your program faster and more defensible. The judgment stays where regulators expect it: with your people.

Next step

Bring your security review. We like those.

Walk through segmentation, provenance, model routing, and audit sealing with the team, against your own evaluation checklist.