GOVERNANCE, COMPLIANCE & AI ACCOUNTABILITY

Autonomy that can survive being asked hard questions afterward.

This page is written for the conversation that follows an incident, not just the one before it — including the parts of the governance model that are still drafts.

Generated continuously, not assembled for an audit.

Predator's Governance & Risk Intelligence layer (L5) maintains mapping against the following frameworks as a byproduct of normal operation.

NIST CSF
Mapped
ISO 27001
Mapped
SOC 2
Mapped
PCI-DSS
Mapped
HIPAA
Mapped
FedRAMP
Mapped
CIS Controls
Mapped
GDPR
Mapped

Three rules that hold regardless of confidence score.

01

Hard guardrails, not soft preferences

Certain actions — deleting production databases, modifying billing configuration — are never permitted autonomously. This is enforced architecturally at L6 before any action reaches the Remediation Fabric, not configured as a tunable preference.

02

Evidence before action

No autonomous action executes without a logged evidence trail and a plain-language reasoning record. The console demo on this site shows this exact record for every incident, autonomous or escalated.

03

Confidence has a ceiling on authority

A high confidence score expands what Predator may do autonomously within its governance tier — it never removes the human approval requirement for actions outside that tier, regardless of how confident the system is.

Who answers for what.

Platform
Evidence accuracy, reasoning explainability, rollback availability, governance enforcement, and safe-mode activation as designed and documented.
Analyst
Approving high-impact actions, resolving governance exceptions, and validating recommendations at the tiers defined in the governance envelope.
Executive (L6)
Defining risk appetite and governance boundaries, and approving the highest-impact tier of actions. Accountability for every Predator action ultimately sits here — by design, not by exception.

Built, deployed, and running — not conceptual.

Every layer described on this site reflects production architecture.

Everything described in Platform Architecture and demonstrated in the console demo reflects the platform as currently built.

Have a compliance or legal question we didn't cover?

We'd rather answer it directly than have you guess.