Security and governance built into the platform, not bolted on.
Zero-trust architecture, sub-millisecond policy enforcement, and sovereign deployment options — designed for regulated environments from day one.
Procurement-ready trust portal
trust.budecosystem.com — SOC 2 / ISO 27001 reports, subprocessor list, security policies, pen-test summaries. Self-serve, NDA-gated.
An honest table. Dated, not aspirational.
Reports available on request under NDA. As of Q2 2026.
| Framework | Status | Notes |
|---|---|---|
| SOC 2 Type II | Certified | Annual audit · report on request |
| ISO 27001 | Certified | Information security management, full platform scope |
| EU AI Act | Ready | Article-level mapping available below |
| HIPAA | Compliant by deployment | BAA available · sovereign mode |
| FedRAMP | Roadmap · Q3 2026 | In progress with sponsoring agency |
| PCI-DSS | Adjacent / by deployment | Scoped per customer environment |
Four guarantees, native to every layer.
Zero-trust
Every call authenticated, every action authorized — no implicit trust between components.
RBAC + ABAC
Fine-grained policy at the agent and tool level, not just the API boundary.
Audit logging
Tamper-evident, exportable, with configurable retention.
Data residency
Your data never leaves your environment. No egress paths by default.
Governance at 0.70ms.
Real-time guardrails enforced in-line with inference. PII detection, jailbreak resistance, and policy compliance — without a latency penalty. 8.39ms on CPU versus 18–19ms on a $15K GPU; roughly 239× cheaper per million guardrail calls.
Read SENTRY documentationReference deployments across three jurisdictions.
India
National-scale government deployment — air-gapped, on-prem, 60K+ users.
UAE
In-country sovereign reference, data resident within national borders.
South Korea
Regulated-industry deployment under local data-protection regime.
Mapped article by article.
High-risk system requirements enforce August 2026. The full mapping is in the whitepaper; a summary follows.
| Article | Requirement | Bud capability |
|---|---|---|
| Art. 9 | Risk management system | SENTRY policy engine + continuous evaluation gates |
| Art. 10 | Data governance | Bud Model Foundry lineage + dataset versioning |
| Art. 12 | Record-keeping & logging | Tamper-evident audit trail, exportable |
| Art. 14 | Human oversight | Bud Studio approval flows + override controls |
Where your data goes — and where it doesn't.
Questions for our security team?
A direct line to the team that owns these answers — not a generic contact form.
Put your data on it.
The fastest way to see what an integrated AI operating system does for your enterprise is a proof-of-concept on your infrastructure, with your data.