The Buyer's Toolkit
Compliance

HIPAA-Grade Lockdown Audit

The criterion: For every safeguard, ask one thing: is it enforced by the architecture — the system won't let it be bypassed — or just requested by a policy that holds only while everyone follows it? One survives a bad day, a new hire, and a vendor's terms change. The other is a promise.

Everything runs in your browser. Nothing you mark here is sent anywhere — the audit is yours to keep.

How to use: the rows start on a typical cloud-AI office — set each to where you actually stand. The verdict scores it Built in (the architecture enforces it), Paper only (a handbook rule), or Gap (nothing's stopping it). For sensitive data, treat Unsure as a gap until proven.

Safeguard Your current state Verdict
Least-privilege access Access control Each person reaches only the data their role needs — the front desk can't open the partner's files. Locked down: per-role, per-person limits the system enforces, not an honor system.
Your current state
Verdict Paper only
Strong authentication Authentication The system verifies who's actually logged in before it shows anything — real identities, not a shared login. Locked down: every session tied to a verified person, MFA on anything sensitive.
Your current state
Verdict Built in
Sealed mode for crown-jewel data Access control Your most-sensitive records go into a locked mode nothing pulls them out of — not exported, not sent to a vendor, not trained on. Locked down: protected records sealed to the machine, no path out even for an admin.
Your current state
Verdict Gap
Unbypassable audit log Audit controls Every read and write is logged, with no way around the log — including for administrators. Locked down: a tamper-evident log of every access, no backdoor that skips it.
Your current state
Verdict Gap
Record integrity Integrity Records can't be silently altered; every change is attributable and reversible. Locked down: every change attributed to a person and verifiable after the fact.
Your current state
Verdict Paper only
Encryption at rest & in transit Transmission security Data is encrypted on disk and on the wire, with keys you control. Locked down: encrypted everywhere, and the keys are yours — not only the vendor's.
Your current state
Verdict Built in
No third-party read access Beyond HIPAA No outside party — including your AI vendor — can read what your team types. A vendor who can read everything is a third party on every privileged conversation. Locked down: nobody outside your walls can read your prompts or files, ever.
Your current state
Verdict Gap
Data stays on your machine Transmission security Your prompts and files physically stay on your hardware — never sent to a vendor's servers, never kept to train a model. Locked down: zero egress — nothing leaves the building, nothing trains someone else's model.
Your current state
Verdict Gap
built into the architecture
only written in a policy
gaps — nothing's stopping it
enforced-grade posture

Paperwork or architecture — the one question under all of them

HIPAA, attorney-client privilege, trade-secret protection — none of them are paperwork problems. They're architecture problems. A policy asks people to behave; architecture enforces it whether they do or not. A handbook line saying "don't put client data in the AI" holds right up until someone does — and a vendor who can read everything your team types is a third party on every privileged conversation, whose terms can change next quarter. The safeguards you can mark Built in are the ones that survive a bad day. The rest are promises.

The vendor test: for each safeguard, ask any AI vendor one thing — is this enforced by the architecture, or is it in my policy? Then the question underneath all of them: can anyone outside my walls read my data? If the honest answer is yes, no amount of paperwork closes that gap. The only setup that turns every row into "Built in" is one where the data never leaves your machine to begin with — nothing to disclose, nothing to egress, nothing for a vendor's terms to reach.

Count your "Paper only" and "Gap" rows. Each one is a protection you're hoping holds, not one you know does. FactoryOS is built so every row above is "Built in" — because the data never leaves your machine.

Lock it down by architecture