Rōvn · Investor Room
AI agent: checking…
All sections
Compliance & Security

Compliance Binder

Current truthRōvn master canon generation 8 · effective 2026-07-21. Earlier dated diligence documents are historical snapshots, not current deployment proof.Ask the canon-grounded agent →
AI Diligence Console

Compliance Binder

Reviewed: 2026-07-22 · Canon: generation 8, effective 2026-07-21 · Posture: pre-launch. The compliance trajectory is active and documented; no certificate is claimed that we do not hold.


1. SOC 2

ItemStatus
SOC 2 Type IIProgram in progress. Observation window opening Q3 2026; report target Q3 2027 after the 12-month window closes. Detail in 06.3.
ScopeSecurity, Availability, Confidentiality, Processing Integrity, Privacy
AuditorIndependent CPA firm; stated only when the engagement letter is on file

Do not claim: SOC 2 certified, a Type II certificate, an interim Type I attestation, or a specific control count.

Do claim: a documented Type II program with the dates above, stated with current evidence.


2. HIPAA

ItemStatus
PostureHIPAA-aligned, BAA available. The only approved phrasing. Detail in 06.2.
Vendor BAAsGating register in 06.4: executed before any real PHI, stated only with signed documents on file
Customer BAATemplate maintained under outside counsel; summary at 08.9
Current data stateSynthetic only; no PHI in the deployed system; real-data mode fails closed

Do not claim: HIPAA certified (no such certification exists), HIPAA compliant as a marketing line, or zero-breach claims built on an empty ledger.

Do claim: HIPAA-aligned architecture, BAA available, PHI-minimized design, and the gating discipline above.


3. NCQA CVO

ItemStatus
CertificationNot NCQA-certified. No filing has been made.
TrajectoryThe CVO clock starts from the first real pilot verifications, by design, because the 18-to-24-month certification path cannot be compressed later. Detail in 06.8.
DelegationNo delegation agreement is signed. A delegation-capable partner is pursued in parallel per the GTM plan.

Do not claim: NCQA-certified, NCQA CVO certified, or NCQA filed.

Do claim: an NCQA-aligned architecture direction and a documented certification trajectory that begins with real pilot verifications.


4. Primary source verification evidence

ItemStatus
PSV evidence designEvery verification is designed to produce a source receipt: source, timestamp, response, hash, evidence class
Surveyor relationshipRōvn is a vendor, not a surveyed entity. Customer facilities carry their own accreditation and use Rōvn-preserved PSV evidence inside their own survey obligations
Source adaptersAdapter states vary (registered, contract-ready, sandbox, live are different states). A source is described as live only with contract, credentials, and current transport proof

5. Other regulatory alignment

FrameworkStatusNotes
FCRA and consumer reportingCounsel-gatedWhether any Rōvn workflow makes it a consumer reporting agency is a counsel determination; adverse-action workflow design follows that determination. Recommended defaults pending counsel (Jason Acevedo, Klehr Harrison)
Title VII and employment agency lawDesigned stack, counsel-gatedNo placement fee defeats fee-gated state licensing theories but is legally irrelevant to Title VII section 701(c). The answer is the worker-agent stack: opt-in, protected-class allow-list at the schema layer, human-authored requirements, a published bias audit before any ranking or contact surface ships, and a human decision on every contact. See 06.5 and 08.10
State privacy (CCPA and state rights)Aligned by designWorker-controlled data model, export and deletion rights in the product design
GDPRNot in scopeUS-only operations at this stage
FedRAMPNot pursuedCommercial sector focus
HITRUST CSFNot certified, not scheduledCustomer-pull dependent; revisited when a buyer requires it

6. Compliance evidence packaging

For each enterprise pilot conversation, Rōvn provides:

  1. SOC 2 program status with current evidence (06.3)
  2. HIPAA posture memo and customer BAA template (06.2, 08.9)
  3. Sub-processor registry and flow-down (06.11, 08.11)
  4. Security posture and threat model (06.1, 06.9)
  5. Incident response runbook (06.10)
  6. Pentest summary once completed (target Q4 2026)

7. What we do not do

  • We do not store real PHI in the deployed system today, and real-data mode fails closed until the activation gates pass.
  • We do not transmit PHI to vendors without an executed agreement covering it.
  • We do not make any credentialing, privileging, hiring, or clinical decision by AI. Named humans decide.
  • We do not sell, share, or analytically reuse worker data outside the consent grant.
  • We do not present a demo URL, a green test suite, or a deployed surface as production or legal proof.

8. Open compliance items

  • SOC 2 Type II observation window and report per the 06.3 dates
  • External pentest (target Q4 2026)
  • Vendor BAA execution and re-papering under Rōvn, Inc. ahead of real-data activation
  • NCQA CVO clock start from first real pilot verifications; delegation partner signature
  • Counsel determinations on FCRA scope and the Title VII opinion before any agent-contact surface ships
  • Known trust-hardening work remains open in the deployed backend and is gated ahead of real-data activation

End of compliance binder.

Ask the AI agent about this section, the raise, compliance posture, or any cross-document question. Grounded in Rōvn canon generation 8, with on-page source citations.

Investor questions run through Google Cloud Vertex AI and are constrained to the hash-pinned Rōvn generation 8 canon. No PHI belongs in this room or its prompts.