For General Counsel
The proof a regulator asks for, before they ask.
Article-mapped evidence. Decision provenance produced continuously. Contestation workflow that supports right-to-challenge obligations emerging across jurisdictions. The artefacts a regulator actually wants, in the format the statutory framework requires.
If the system verifies itself, the evidence will not hold.
Not documentation. Evidence that holds.
Observer Mode shows how your system behaves
Enforce Mode blocks actions before execution
If an action violates policy, it does not run
Regulatory inquiry
What happens when a regulator asks.
An incident occurs. Legal is notified. What follows is reconstruction: relevant staff are interviewed, logs are retrieved from multiple systems, decisions are mapped to regulatory articles, a timeline is assembled, accountability is established. Each step is contested. Each step takes time that is not available. The evidence that emerges was built after the fact. Its integrity is contestable.
Issued by: Commission Nationale de l'Informatique et des Libertés (CNIL)
Issued by: Information Commissioner's Office (ICO)
OBEXGATE produces this record as a continuous side effect of operation. It is not assembled after inquiry begins. It exists before the regulator asks.
The legal problem
Documented intent does not satisfy enforcement requirements.
Most AI governance produces declared posture: policies, attestations, and periodic audits. Regulators are increasingly asking for something different: evidence that the control was active when the decision was made, that the decision is traceable, and that the affected individual can challenge it.
OBEXGATE produces those artefacts as a side effect of operation. Not assembled later. Not reconstructed from logs.
What it produces
Three classes of artefact, every governed decision.
→ Decision provenance
Per-action record of what was evaluated, which frameworks applied, which rule was determinative, and why the decision was made.
→ Article-mapped evidence packs
Evidence mapped to article, principle, or control reference inside the source regulation.
→ Audit lineage
Continuous, verifiable chain across governed events.
→ Contestation record
Challenge, human review, resolution, and supporting evidence.
→ Decommissioning evidence
Structured retirement, access removal, data handling, and sealed closure record.
→ Cross-framework mapping
One event mapped across multiple applicable frameworks.
Evidence flow
How a governed decision becomes a legal record.
| Decision | Governed action evaluated at runtime |
| Evidence | Decision provenance produced as side effect of operation |
| Challenge | Contestation workflow initiated by the affected individual |
| Review | Human review conducted, record produced |
| Resolution | Resolution recorded, audit lineage sealed |
Frameworks covered
Eighty-eight enforcement engines across eight jurisdictions.
Each engine maps to specific articles inside its source regulation. Cross-mapping handles the case where a single decision is governed by multiple frameworks simultaneously.
| Jurisdiction | Frameworks (selection) |
|---|---|
| European Union | EU AI Act, GDPR, DORA, eIDAS, NIS2 |
| United Kingdom | UK GDPR, Data Protection Act 2018, UK DUAA, FCA, PRA |
| United States | HIPAA, FDA, CCPA, NIST AI RMF, FedRAMP, CMMC, SOC 2, ISO 27001 |
| Brazil | LGPD |
| Australia | Privacy Act 1988 |
| New Zealand | Privacy Act 2020 |
| Canada | PIPEDA, AIDA, Ontario Bill 194 |
| Singapore | PDPA, Model AI Governance Framework, MAS FEAT, MAS TRM |
Contestation
Right to challenge an automated decision.
OBEXGATE includes a structured contestation workflow that produces the record of the challenge, the human review, the resolution, and the supporting audit lineage.
This is the artefact that demonstrates substantive compliance, not declared compliance, in regulatory inquiry.
Decommissioning
Structured system retirement, not deletion.
When a governed system is retired, OBEXGATE executes a sequenced teardown: credentials revoked, access removed, retained data purged where required, audit trail closed and sealed, identity record decommissioned. Every phase is recorded as part of the audit lineage.
See the evidence your governance would produce.
Six questions. Personalised regulatory map across the frameworks you are exposed to, statutory exposure detail, three-year operational governance cost basis. Or 30 minutes with the team.