How buyers verify RegAlign®
Everything procurement, infosec and legal teams typically ask for in the first 24 hours of diligence — gathered in one place so you can verify us without an email round-trip. Illustrated with Jersey / JFSC throughout; the chain, methodology and verifier are regime-agnostic.
Pilot-ready for Jersey trust company businesses. Crown Dependencies and UK on the roadmap — same methodology and hash-chained record, source ingestors for JFSC, GFSC, IoM FSA and FCA already shipping.
"What happens if the founder gets hit by a bus?"
Continuity, insurance, liability and exit terms are disclosed and agreed for each engagement. The items below describe the arrangements RegAlign is prepared to enter into where they have been executed as part of a specific engagement; they are not universal, always-on guarantees that apply outside a signed contract.
- Named successor arrangement, agreed per engagement.
- Source-code escrow, offered and executed on a per-engagement basis.
- BCP outline below — pen-test SoW, sub-processors, DPIA.
- Notice and exit-assistance terms disclosed and agreed per engagement.
- Data return and read-only audit-access periods scoped per engagement.
- Insurance and indemnity terms disclosed pre-contract per engagement.
Public registers
Hash-chain verifier
Every audit-trail entry, evidence record and finding can be checked without an account. Hashes are exposed as JSON; chain integrity is auditor-verifiable end-to-end. This is an internal hash chain — tamper-evident to anyone without database-administrator privileges. External anchoring (Rekor, OpenTimestamps or S3 Object Lock) is on the roadmap.
Paste a SHA-256 hash and confirm in seconds. No account, no email, non-PII response.
Open the verifier →Public ratification, override and dismissal rates for Compass AI suggestions across the pilot cohort. Aggregate-only, refreshed daily.
See the numbers →Plain-language walkthrough of the hash chain, non-PII proof shape, Compass labelling, AI content credentials and rate limits.
Read the methodology →A redacted example of what a regulator receives via a one-shot share link — same shape, same integrity block, no live data.
Open sample (PDF) →Public uptime, incident count, mean-time-to-recover and last pen-test date. Honest pilot-stage numbers — "Not measured" rather than fabricated 100%.
See operational metrics →GET /api/public/audit-trail.verifyGET /api/public/evidence.verifyGET /api/public/controls.verifyGET /api/public/findings.verifyGET /api/public/issues.verifyGET /api/public/decisions.verifyLive operational snapshot: /api/public/status — schema version, obligation coverage by jurisdiction, evidence-hash coverage and monitoring coverage.
For your auditor: Chain Verifier Auditor Runbook (PDF) — step-by-step independent integrity check, with working-papers template. Need a named seat on a seeded tenant? Request auditor access →
Diligence pack (PDF)
See full versioned index →Certification roadmap
- JFSC entity registrationLive
RegAlign Limited, Jersey No. 165263.
- UK IPO registered trade markLive
RegAlign®, UK00004283882.
- JOIC data protection registrationLive
Jersey Office of the Information Commissioner, registration No. 103914.
- Hash-chained audit trail (internal, tamper-evident)Live
SHA-256 chain over audit_trail_entries; every evidence record carries an integrity hash. Tamper-evident to anyone without database-administrator privileges. External anchoring (Rekor / OpenTimestamps / S3 Object Lock) on roadmap.
- Public verification endpointsLive
Auditors verify hashes without an account at /api/public/audit-trail.verify, /evidence.verify, /controls.verify, /findings.verify, /issues.verify and /decisions.verify.
- DPIA template + BCP outline + pen-test SoWLive
Pilot pack PDFs available for download below.
- CSA CAIQ v4 — Level 1 self-assessmentLive
Full 197-control Consensus Assessments Initiative Questionnaire self-assessment, with per-question anchors at /trust/caiq for procurement RFP deep-linking. CSA STAR Registry submission in progress.
- Continuous security scanning (Aikido)Live
Aikido runs SAST, secrets, IaC and dependency (SCA) scans across the codebase at workspace level. Findings surface in the build pipeline and are triaged before release. No customer data is shared with the scanner — code only.
- Cloud security posture management (CSPM)Planned
Trigger-tied: CSPM (e.g. Wiz) evaluated and selected within 90 days of first paying customer onboarding, or first enterprise procurement requirement. Platform-level posture today is inherited from Cloudflare Workers and managed Postgres controls.
- Pen test (independent)Planned
Trigger-tied: vendor selected on first paid pilot or first enterprise procurement requirement. Scope of work already published. Report shared under NDA on request.
- SOC 2 Type IPlanned
Trigger-tied: observation window opened within 6 months of Series A close, or before second enterprise customer onboarding. Control set already designed to map onto the Trust Services Criteria.
- SOC 2 Type IIPlanned
Trigger-tied: 12 months after Type I report issued.
- ISO 27001Planned
Trigger-tied: ISMS initiated once headcount supports a dedicated security function (≥1 FTE). ISMS scaffolding already lives in the platform.
What data leaves your tenant
Plain-English summary of which third party sees what. Full named list, regions, DPAs and notification policy are in the sub-processor list (PDF).
| Sub-processor | What it sees | Region |
|---|---|---|
| Supabase Inc. — Postgres, Auth, Storage (operated via Lovable Cloud) | All tenant data at rest; auth identifiers. RLS-enforced tenant isolation; AES-256 at rest; TLS 1.3 in transit. SCCs for any cross-border transfer. | EU (Ireland) / US (controller) |
| Cloudflare (edge, CDN, routing) | Request metadata only. No payload retention beyond routing. | Global edge, EU origin |
| Lovable Cloud (application runtime) | Application runtime memory. No persistent customer data. | EU / UK |
| Lovable AI Gateway → Google Gemini (LLM inference for Compass) | Only the prompt text Compass sends for a given turn. No training on customer data; no retention beyond the inference call. Routed via Lovable's managed gateway to Google Gemini. | EU-preferred (gateway) / US (model) |
| Functional Software Inc. (Sentry) — error monitoring | Server-side error events: stack trace, request path, user UUID (no name or email), browser user-agent. PII scrubbing applied; payloads excluded by default. | US (SCCs) |
| Email delivery (transactional) | Recipient email, subject, message body for system notifications and digests. | EU |
| Source-code escrow agent | Source code only. No customer data. | UK / Jersey |
New sub-processors: 30 days' written notice before processing begins. Right to object: 14 days in writing — terminate the affected service for convenience if we can't accommodate. Full policy in the PDF above.
Data residency & recovery
Primary database and file storage in EU (Ireland). Edge routing global; no payload retained at edge. AI gateway egress from EU. See the sub-processor list.
RTO 24h / RPO 1h for the typical sub-processor outage scenario. Full scenario matrix and honest limitations in the BCP outline.
Security policies
Machine-readable security contact: /.well-known/security.txt.
Need something else?
For deeper diligence (architecture diagrams, data flow maps, vendor security questionnaires, draft pen-test report), write to hello@regalignplatform.com. Full corporate and IP licence chain on the legal page.