The on-premise deployment ships the technical controls these frameworks require — access control, encryption, audit, key management, and recovery — so you can certify Enterprise RAG inside the environment you already own and audit.
What “certification-ready” means. SOC 2 and ISO 27001 certify an organization and its operating environment through an external audit; HIPAA is a legal obligation met with safeguards and BAAs, not a certificate. Because you run the on-premise deployment inside your own infrastructure, the product provides the control implementations and evidence — and you complete the audit within your environment. We supply the control mapping; your team owns the certification.
What it is
An AICPA audit of your controls against the Trust Services Criteria (security, availability, confidentiality). Type II proves they operated over a period.
How ERAG helps
Ship the on-premise deployment with least-privilege access, audit logging, encryption, and backup/restore already in place — then bring that evidence into your Type I or Type II audit.
What it is
Certification of your Information Security Management System (ISMS) and the Annex A controls by an accredited registrar.
How ERAG helps
The platform provides the technical Annex A controls — access control, cryptography, logging, secure operations — to fold into your Statement of Applicability.
What it is
A US legal regime for protected health information (PHI). Not a certificate — you meet the Security Rule safeguards and sign BAAs.
How ERAG helps
Run entirely inside your own environment with no third-party processor, so PHI stays behind your BAA. The Security Rule's technical safeguards map directly to product controls.
Every framework control has a product control behind it.
| Control area | Enterprise RAG capability | Maps to |
|---|---|---|
| Access control | Role-based access (admin / editor / reader), per-tenant isolation, per-document AND per-knowledge-base ACLs enforced inside the retrieval index — never post-filtered. | SOC 2 CC6.1/CC6.3 · ISO A.5.15/A.5.18 · HIPAA §164.312(a)(1) |
| Authentication | MFA/TOTP, SSO via OIDC & SAML, SCIM user provisioning/deprovisioning, PBKDF2-SHA256 password hashing. | SOC 2 CC6.1 · ISO A.5.17 · HIPAA §164.312(d) |
| Session management | Signed, tamper-evident sessions with a configurable lifetime and server-side revocation; API keys with expiry and rotation. | SOC 2 CC6.1 · HIPAA §164.312(a)(2)(iii) automatic logoff |
| Encryption at rest | Document/blob encryption at rest with your own keys; the whole stack runs on storage you own and control. | SOC 2 CC6.1 · ISO A.8.24 · HIPAA §164.312(a)(2)(iv) |
| Encryption in transit | TLS terminated inside your network; no data leaves your perimeter — air-gapped deployment supported. | SOC 2 CC6.7 · ISO A.8.24 · HIPAA §164.312(e)(1) |
| Audit logging | Immutable audit events for security-relevant actions, exportable to your SIEM for retention and review. | SOC 2 CC7.2 · ISO A.8.15 · HIPAA §164.312(b) |
| Data integrity | Answers are grounded and cited to their source passages; ACL filtering happens inside the index so a record a caller can't see never reaches a prompt. | SOC 2 CC6.1 · HIPAA §164.312(c)(1) |
| Data minimization | Optional PII redaction at ingestion; content moderation; store-query controls to avoid retaining question text. | ISO A.8.11 · GDPR Art. 5 · HIPAA minimum-necessary |
| Availability & recovery | Scheduled backups and restore for disaster recovery; deployable HA on Kubernetes. | SOC 2 A1.2 · ISO A.8.13/A.5.29 · HIPAA §164.308(a)(7) |
| Sovereignty & isolation | Runs in your VPC, datacenter, or fully offline; local/self-hosted models mean no document or prompt is sent to an external AI provider. | ISO A.5.23 · HIPAA §164.308(b) · GDPR residency |
Framework references are indicative and shown to orient your auditor — final scoping and applicability are determined during your assessment.
Who does what.
Request the on-premise deployment and our team will share the hardening guide and the full control-to-framework mapping your assessor needs to scope SOC 2, ISO 27001, or a HIPAA program.
Request on-premise