On-premise · Compliance

Certification-ready for SOC 2, ISO 27001 & HIPAA.

The on-premise deployment ships the technical controls these frameworks require — access control, encryption, audit, key management, and recovery — so you can certify Enterprise RAG inside the environment you already own and audit.

SOC 2 ISO/IEC 27001 HIPAA

What “certification-ready” means. SOC 2 and ISO 27001 certify an organization and its operating environment through an external audit; HIPAA is a legal obligation met with safeguards and BAAs, not a certificate. Because you run the on-premise deployment inside your own infrastructure, the product provides the control implementations and evidence — and you complete the audit within your environment. We supply the control mapping; your team owns the certification.

SOC 2

What it is

An AICPA audit of your controls against the Trust Services Criteria (security, availability, confidentiality). Type II proves they operated over a period.

How ERAG helps

Ship the on-premise deployment with least-privilege access, audit logging, encryption, and backup/restore already in place — then bring that evidence into your Type I or Type II audit.

ISO/IEC 27001

What it is

Certification of your Information Security Management System (ISMS) and the Annex A controls by an accredited registrar.

How ERAG helps

The platform provides the technical Annex A controls — access control, cryptography, logging, secure operations — to fold into your Statement of Applicability.

HIPAA

What it is

A US legal regime for protected health information (PHI). Not a certificate — you meet the Security Rule safeguards and sign BAAs.

How ERAG helps

Run entirely inside your own environment with no third-party processor, so PHI stays behind your BAA. The Security Rule's technical safeguards map directly to product controls.

Control mapping

Every framework control has a product control behind it.

Control areaEnterprise RAG capabilityMaps to
Access controlRole-based access (admin / editor / reader), per-tenant isolation, per-document AND per-knowledge-base ACLs enforced inside the retrieval index — never post-filtered.SOC 2 CC6.1/CC6.3 · ISO A.5.15/A.5.18 · HIPAA §164.312(a)(1)
AuthenticationMFA/TOTP, SSO via OIDC & SAML, SCIM user provisioning/deprovisioning, PBKDF2-SHA256 password hashing.SOC 2 CC6.1 · ISO A.5.17 · HIPAA §164.312(d)
Session managementSigned, tamper-evident sessions with a configurable lifetime and server-side revocation; API keys with expiry and rotation.SOC 2 CC6.1 · HIPAA §164.312(a)(2)(iii) automatic logoff
Encryption at restDocument/blob encryption at rest with your own keys; the whole stack runs on storage you own and control.SOC 2 CC6.1 · ISO A.8.24 · HIPAA §164.312(a)(2)(iv)
Encryption in transitTLS terminated inside your network; no data leaves your perimeter — air-gapped deployment supported.SOC 2 CC6.7 · ISO A.8.24 · HIPAA §164.312(e)(1)
Audit loggingImmutable audit events for security-relevant actions, exportable to your SIEM for retention and review.SOC 2 CC7.2 · ISO A.8.15 · HIPAA §164.312(b)
Data integrityAnswers are grounded and cited to their source passages; ACL filtering happens inside the index so a record a caller can't see never reaches a prompt.SOC 2 CC6.1 · HIPAA §164.312(c)(1)
Data minimizationOptional PII redaction at ingestion; content moderation; store-query controls to avoid retaining question text.ISO A.8.11 · GDPR Art. 5 · HIPAA minimum-necessary
Availability & recoveryScheduled backups and restore for disaster recovery; deployable HA on Kubernetes.SOC 2 A1.2 · ISO A.8.13/A.5.29 · HIPAA §164.308(a)(7)
Sovereignty & isolationRuns in your VPC, datacenter, or fully offline; local/self-hosted models mean no document or prompt is sent to an external AI provider.ISO A.5.23 · HIPAA §164.308(b) · GDPR residency

Framework references are indicative and shown to orient your auditor — final scoping and applicability are determined during your assessment.

Shared responsibility

Who does what.

Enterprise RAG provides

  • The product-side technical controls above, shipped and configurable
  • Encryption at rest, RBAC, ACLs, MFA, SSO/SCIM, audit events, backups
  • A hardened deployment guide + this control-to-framework mapping as audit evidence
  • Local-only inference so data never leaves your perimeter

Your organization owns

  • The audit itself — engaging a CPA firm (SOC 2) or accredited registrar (ISO 27001)
  • Your ISMS, risk assessments, policies, and personnel/administrative safeguards
  • Operating the environment: TLS certs, key custody, network segmentation, patching, IdP
  • Signing BAAs (HIPAA) with your customers and any of your own subprocessors

Get the control mapping for your audit

Request the on-premise deployment and our team will share the hardening guide and the full control-to-framework mapping your assessor needs to scope SOC 2, ISO 27001, or a HIPAA program.

Request on-premise

← Back to on-premise