Cartridges (Framework & Packs)
All cartridges share the same Framework V1: foldering, registry, lifecycle hooks (pre/post/HITL), evidence schema, tests, and Mapping Manifests.
Read the FrameworkCompliance Cartridges by Maturity
Coverage is mixed across preview, pilot hardening, and planned packs, with runtime enforcement where implemented.
EU AI Act
PreviewHigh-risk AI classification, prohibited practices, transparency requirements
GDPR
PreviewPII detection, data minimization, consent management, right to erasure
HIPAA
PreviewPHI protection, access controls, audit trails, 7-year retention
SOC 2
PreviewSecurity, availability, processing integrity, confidentiality, privacy
ISO 27001
PreviewInformation security management system controls and risk assessment
ISO/IEC 42001
PreviewAI management system standard for responsible AI development
SOX
PreviewFinancial reporting controls, audit trails, data integrity for public companies
CCPA
PreviewCalifornia consumer rights, data disclosure, opt-out mechanisms
HITRUST CSF
PreviewHealthcare security framework combining HIPAA, NIST, and ISO standards
NIST AI RMF
PreviewAI risk management framework for trustworthy and responsible AI
QiXHealth Pilot Showcase
QiXHealth provides HIPAA-aligned EHR integration patterns with runtime PHI controls; regulated pilot hardening is in progress.
Mode Switches
Adopt in Shadow (observe), Graduated (warn), Strict (enforce).
Policy → Detector → Override UI → Audit Log
Framework V1 Details
| Badge | Cartridge | Scope | Status | Status Report | Evidence Hub | Downloads |
|---|---|---|---|---|---|---|
| | EU AI Act | High-risk AI systems, banned practices | Available | View Report | View Evidence | |
| | GDPR | PII detection, data minimization, consent | Available | View Report | View Evidence | |
| | HIPAA | PHI protection, access controls, audit trails | Available | Coming Soon | View Evidence | |
| | SOC 2 | Security, availability, processing integrity | Available | Coming Soon | View Evidence | |
| | ISO 27001 | Information security management | Available | Coming Soon | View Evidence | |
| | ISO/IEC 42001 | AI management system standard | Available | Coming Soon | View Evidence | |
| | SOX | Financial reporting controls, audit trails | Available | Coming Soon | View Evidence | |
| | CCPA | Consumer rights, data disclosure, opt-out | Available | Coming Soon | View Evidence | |
| | HITRUST | Healthcare security framework | Available | Coming Soon | View Evidence | |
| | NIST AI RMF | AI risk management framework | Available | Coming Soon | View Evidence | |
| | FDA 21 CFR Part 11 | Electronic records and signatures | In Development | Coming Soon | View Evidence | In Development |