RegAlgn®
Trust Centre

How buyers verify RegAlign®

Everything procurement, infosec and legal teams typically ask for in the first 24 hours of diligence — gathered in one place so you can verify us without an email round-trip. Illustrated with Jersey / JFSC throughout; the chain, methodology and verifier are regime-agnostic.

Regimes supported
JFSC· Jersey· pilot-readyGFSC· Guernsey· on the roadmapIoM FSA· Isle of Man· on the roadmapFCA· UK· on the roadmap

Pilot-ready for Jersey trust company businesses. Crown Dependencies and UK on the roadmap — same methodology and hash-chained record, source ingestors for JFSC, GFSC, IoM FSA and FCA already shipping.

Single-founder continuity — answered first

"What happens if the founder gets hit by a bus?"

Continuity, insurance, liability and exit terms are disclosed and agreed for each engagement. The items below describe the arrangements RegAlign is prepared to enter into where they have been executed as part of a specific engagement; they are not universal, always-on guarantees that apply outside a signed contract.

Public registers

Hash-chain verifier

Every audit-trail entry, evidence record and finding can be checked without an account. Hashes are exposed as JSON; chain integrity is auditor-verifiable end-to-end. This is an internal hash chain — tamper-evident to anyone without database-administrator privileges. External anchoring (Rekor, OpenTimestamps or S3 Object Lock) is on the roadmap.

Self-serve integrity check

Paste a SHA-256 hash and confirm in seconds. No account, no email, non-PII response.

Open the verifier →
Compass AI methodology & outcomes

Public ratification, override and dismissal rates for Compass AI suggestions across the pilot cohort. Aggregate-only, refreshed daily.

See the numbers →
How we prove this

Plain-language walkthrough of the hash chain, non-PII proof shape, Compass labelling, AI content credentials and rate limits.

Read the methodology →
Sample regulator pack

A redacted example of what a regulator receives via a one-shot share link — same shape, same integrity block, no live data.

Open sample (PDF) →
Operational metrics

Public uptime, incident count, mean-time-to-recover and last pen-test date. Honest pilot-stage numbers — "Not measured" rather than fabricated 100%.

See operational metrics →
GET /api/public/audit-trail.verifyGET /api/public/evidence.verifyGET /api/public/controls.verifyGET /api/public/findings.verifyGET /api/public/issues.verifyGET /api/public/decisions.verify

Live operational snapshot: /api/public/status — schema version, obligation coverage by jurisdiction, evidence-hash coverage and monitoring coverage.

For your auditor: Chain Verifier Auditor Runbook (PDF) — step-by-step independent integrity check, with working-papers template. Need a named seat on a seeded tenant? Request auditor access →

Diligence pack (PDF)

See full versioned index →

Certification roadmap

What data leaves your tenant

Plain-English summary of which third party sees what. Full named list, regions, DPAs and notification policy are in the sub-processor list (PDF).

Sub-processorWhat it seesRegion
Supabase Inc. — Postgres, Auth, Storage (operated via Lovable Cloud)All tenant data at rest; auth identifiers. RLS-enforced tenant isolation; AES-256 at rest; TLS 1.3 in transit. SCCs for any cross-border transfer.EU (Ireland) / US (controller)
Cloudflare (edge, CDN, routing)Request metadata only. No payload retention beyond routing.Global edge, EU origin
Lovable Cloud (application runtime)Application runtime memory. No persistent customer data.EU / UK
Lovable AI Gateway → Google Gemini (LLM inference for Compass)Only the prompt text Compass sends for a given turn. No training on customer data; no retention beyond the inference call. Routed via Lovable's managed gateway to Google Gemini.EU-preferred (gateway) / US (model)
Functional Software Inc. (Sentry) — error monitoringServer-side error events: stack trace, request path, user UUID (no name or email), browser user-agent. PII scrubbing applied; payloads excluded by default.US (SCCs)
Email delivery (transactional)Recipient email, subject, message body for system notifications and digests.EU
Source-code escrow agentSource code only. No customer data.UK / Jersey

New sub-processors: 30 days' written notice before processing begins. Right to object: 14 days in writing — terminate the affected service for convenience if we can't accommodate. Full policy in the PDF above.

Data residency & recovery

Data residency

Primary database and file storage in EU (Ireland). Edge routing global; no payload retained at edge. AI gateway egress from EU. See the sub-processor list.

Recovery objectives

RTO 24h / RPO 1h for the typical sub-processor outage scenario. Full scenario matrix and honest limitations in the BCP outline.

Security policies

Machine-readable security contact: /.well-known/security.txt.

Need something else?

For deeper diligence (architecture diagrams, data flow maps, vendor security questionnaires, draft pen-test report), write to hello@regalignplatform.com. Full corporate and IP licence chain on the legal page.