Compliance Binder
Reviewed: 2026-07-22 · Canon: generation 8, effective 2026-07-21 · Posture: pre-launch. The compliance trajectory is active and documented; no certificate is claimed that we do not hold.
1. SOC 2
| Item | Status |
|---|---|
| SOC 2 Type II | Program in progress. Observation window opening Q3 2026; report target Q3 2027 after the 12-month window closes. Detail in 06.3. |
| Scope | Security, Availability, Confidentiality, Processing Integrity, Privacy |
| Auditor | Independent CPA firm; stated only when the engagement letter is on file |
Do not claim: SOC 2 certified, a Type II certificate, an interim Type I attestation, or a specific control count.
Do claim: a documented Type II program with the dates above, stated with current evidence.
2. HIPAA
| Item | Status |
|---|---|
| Posture | HIPAA-aligned, BAA available. The only approved phrasing. Detail in 06.2. |
| Vendor BAAs | Gating register in 06.4: executed before any real PHI, stated only with signed documents on file |
| Customer BAA | Template maintained under outside counsel; summary at 08.9 |
| Current data state | Synthetic only; no PHI in the deployed system; real-data mode fails closed |
Do not claim: HIPAA certified (no such certification exists), HIPAA compliant as a marketing line, or zero-breach claims built on an empty ledger.
Do claim: HIPAA-aligned architecture, BAA available, PHI-minimized design, and the gating discipline above.
3. NCQA CVO
| Item | Status |
|---|---|
| Certification | Not NCQA-certified. No filing has been made. |
| Trajectory | The CVO clock starts from the first real pilot verifications, by design, because the 18-to-24-month certification path cannot be compressed later. Detail in 06.8. |
| Delegation | No delegation agreement is signed. A delegation-capable partner is pursued in parallel per the GTM plan. |
Do not claim: NCQA-certified, NCQA CVO certified, or NCQA filed.
Do claim: an NCQA-aligned architecture direction and a documented certification trajectory that begins with real pilot verifications.
4. Primary source verification evidence
| Item | Status |
|---|---|
| PSV evidence design | Every verification is designed to produce a source receipt: source, timestamp, response, hash, evidence class |
| Surveyor relationship | Rōvn is a vendor, not a surveyed entity. Customer facilities carry their own accreditation and use Rōvn-preserved PSV evidence inside their own survey obligations |
| Source adapters | Adapter states vary (registered, contract-ready, sandbox, live are different states). A source is described as live only with contract, credentials, and current transport proof |
5. Other regulatory alignment
| Framework | Status | Notes |
|---|---|---|
| FCRA and consumer reporting | Counsel-gated | Whether any Rōvn workflow makes it a consumer reporting agency is a counsel determination; adverse-action workflow design follows that determination. Recommended defaults pending counsel (Jason Acevedo, Klehr Harrison) |
| Title VII and employment agency law | Designed stack, counsel-gated | No placement fee defeats fee-gated state licensing theories but is legally irrelevant to Title VII section 701(c). The answer is the worker-agent stack: opt-in, protected-class allow-list at the schema layer, human-authored requirements, a published bias audit before any ranking or contact surface ships, and a human decision on every contact. See 06.5 and 08.10 |
| State privacy (CCPA and state rights) | Aligned by design | Worker-controlled data model, export and deletion rights in the product design |
| GDPR | Not in scope | US-only operations at this stage |
| FedRAMP | Not pursued | Commercial sector focus |
| HITRUST CSF | Not certified, not scheduled | Customer-pull dependent; revisited when a buyer requires it |
6. Compliance evidence packaging
For each enterprise pilot conversation, Rōvn provides:
- SOC 2 program status with current evidence (06.3)
- HIPAA posture memo and customer BAA template (06.2, 08.9)
- Sub-processor registry and flow-down (06.11, 08.11)
- Security posture and threat model (06.1, 06.9)
- Incident response runbook (06.10)
- Pentest summary once completed (target Q4 2026)
7. What we do not do
- We do not store real PHI in the deployed system today, and real-data mode fails closed until the activation gates pass.
- We do not transmit PHI to vendors without an executed agreement covering it.
- We do not make any credentialing, privileging, hiring, or clinical decision by AI. Named humans decide.
- We do not sell, share, or analytically reuse worker data outside the consent grant.
- We do not present a demo URL, a green test suite, or a deployed surface as production or legal proof.
8. Open compliance items
- SOC 2 Type II observation window and report per the 06.3 dates
- External pentest (target Q4 2026)
- Vendor BAA execution and re-papering under Rōvn, Inc. ahead of real-data activation
- NCQA CVO clock start from first real pilot verifications; delegation partner signature
- Counsel determinations on FCRA scope and the Title VII opinion before any agent-contact surface ships
- Known trust-hardening work remains open in the deployed backend and is gated ahead of real-data activation
End of compliance binder.