نظرة عامة على
Posture

Our certifications in progress, operational regulatory frameworks, and AI-specific alignment — written for legal, risk, and procurement teams.

Effective Date: May 6, 2026
Last Updated: May 6, 2026

This page describes the compliance posture of Obscurae Intelligence Inc. (“FalsiFind”) for the FalsiFind deepfake detection platform (“Platform”). It is written for legal, risk, and procurement teams at financial institutions, fintechs, and other regulated buyers.

We are direct about what is in progress, what is operational, and what we are aligning to. We do not claim certifications we do not hold. We do not use compliance language as marketing. Where work is underway, we say so and we say where we are.

١. كيفية قراءة هذه الصفحة

We organize our compliance posture into three layers:

  1. Certifications and Attestations in Progress. External, independent assessments we are working toward, with current status and target timing.
  2. Operational Compliance. Regulatory frameworks under which we operate today, with the controls, processes, and documentation that support that posture.
  3. AI-Specific Frameworks. Voluntary and emerging frameworks we have adopted because they are the right substantive baseline for an AI product, regardless of whether external attestation exists yet.

Detailed evidence (control descriptions, sub-processor list, DPA, transfer documentation, penetration test summary letters, and where issued, audit reports) is available to enterprise customers and qualified prospects under NDA.

٢. الشهادات والاعتمادات قيد التنفيذ

These are external, independent assessments we are pursuing. We use the word “in progress” deliberately. We do not represent that any of these is complete until the relevant report or certificate has been issued.

2.1 SOC 2 Type II

Status: In progress.
Approximate readiness: ~85%, as tracked against our internal control matrix.
Trust services criteria: Security, Availability, and Confidentiality are in scope. Processing Integrity and Privacy may be added in a subsequent examination.
What we have done: documented control owners and evidence-collection procedures, deployed continuous control monitoring tooling, completed a readiness assessment, and engaged a qualified independent auditor.
What is left: completing the observation period for the Type II report and the independent auditor’s examination.
What this means for buyers: until the Type II report is issued, we cannot represent that we are SOC 2 Type II compliant. We can, under NDA, share our control matrix, readiness assessment, and progress against criteria.

2.2 ISO/IEC 27001

Status: In progress.
Approximate readiness: ~75% against the ISO/IEC 27001:2022 control set.
What we have done: scoped the Information Security Management System (ISMS), documented Statement of Applicability, established the risk management process, and aligned policies to Annex A controls.
What is left: maturing internal audit cycles, completing the management review program, and engaging an accredited certification body for Stage 1 and Stage 2 audits.
What this means for buyers: until certification is issued, we cannot represent that we are ISO/IEC 27001 certified. We can, under NDA, share our ISMS scope, Statement of Applicability, and current control coverage.

2.3 ISO/IEC 27017 and 27018

Status: Aligned, formal certification deferred.
We track 27017 (cloud-specific controls) and 27018 (cloud PII controls) as supplements to 27001. We will pursue formal certification once 27001 is complete.

2.4 SOC 1 Type II

Status: Not pursued at this time. We will reassess when customer financial-reporting impact warrants it.

٣. الامتثال التشغيلي

These are the regulatory frameworks under which we operate today. The controls, policies, and processes that support them are described in detail on our Security page and in our Privacy Policy.

3.1 GDPR and UK GDPR

Status: Operational.
We process personal information consistent with the EU General Data Protection Regulation and the UK GDPR. Specifically, we:

  • Distinguish controller and processor roles and document them per data flow
  • Maintain Records of Processing Activities (Article 30)
  • Sign Data Processing Addenda with enterprise customers, incorporating Standard Contractual Clauses and the UK International Data Transfer Addendum where applicable
  • Conduct Transfer Impact Assessments for transfers to third countries
  • Honor data subject rights (access, rectification, erasure, restriction, objection, portability, withdrawal of consent) within statutory timelines
  • Maintain a written breach notification process aligned with the Article 33 supervisory authority notification requirement (72 hours) and Article 34 individual notification requirements
  • Operate under appointed Article 27 representatives in the EU and the UK (current status: representatives to be appointed, placeholders maintained on the Privacy Policy)

Approximate readiness: ~90%, with the Article 27 representative appointments as the remaining open item.

3.2 CCPA / CPRA and US State Comprehensive Privacy Laws

Status: Operational.
We honor consumer privacy rights under the California Consumer Privacy Act as amended by the California Privacy Rights Act, and under the comprehensive privacy laws of states including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and others as they take effect. We:

  • Honor access, deletion, correction, opt-out of sale and sharing, and limit-use rights
  • Honor Global Privacy Control as a valid opt-out signal
  • Maintain service-provider contracts with sub-processors that comply with CCPA/CPRA service-provider requirements
  • Do not sell personal information. Where Marketing cookies are enabled by a Website visitor, that activity may be classified as a “sale” or “share” under California law; visitors can opt out at any time through the cookie banner

3.3 PIPEDA and Quebec Law 25

Status: Operational readiness.
For Canadian personal information, we operate consistent with PIPEDA principles and with the additional obligations under Quebec’s Law 25, including transparency about automated decision-making, breach notification to the Commission d’acces a l’information where applicable, and cross-border transfer disclosures.

3.4 NYDFS Part 500 Alignment

Status: Operational alignment for financial-sector deployment.
The Platform is designed to support customer obligations under New York Department of Financial Services 23 NYCRR Part 500, as amended through the Second Amendment, including:

  • Multi-factor authentication coverage (the universal MFA requirement that took effect 1 November 2025)
  • Asset inventory support
  • Audit trail and access logging
  • Incident reporting alignment with the 72-hour cybersecurity event notification and 24-hour extortion-payment notification with explanation requirement
  • Data retention and disposal practices

NYDFS regulated entities remain responsible for their own Part 500 compliance, including the dual-signature CEO and CISO certification requirement. We support customer compliance with documentation and audit artifacts.

3.5 GLBA Safeguards Rule Alignment

Status: Operational alignment.
Where the Platform processes nonpublic personal information of a financial institution’s customers, we operate as a service provider under the Safeguards Rule. Our administrative, technical, and physical safeguards align with the Rule’s requirements, and our Data Processing Addendum reflects the contractual obligations financial-institution customers need from a service provider.

3.6 HIPAA

Status: Available where required, by exception.
The Platform is not generally directed to healthcare workflows. Where a customer has a use case that involves Protected Health Information, we will discuss whether and how to enter into a Business Associate Agreement and apply the additional controls that posture requires.

3.7 PCI DSS

Status: Not in scope by design.
We do not process, store, or transmit cardholder data through the Platform.

3.8 Cross-Border Data Transfers

Status: Operational.
We rely on the EU-US Data Privacy Framework and the UK Extension and Swiss-US DPF where the receiving entity is certified, on Standard Contractual Clauses with Transfer Impact Assessments where DPF coverage does not apply, on the UK International Data Transfer Agreement and Addendum for UK transfers, and on other valid mechanisms as recognized under applicable law.

٤. أطر خاصة بالذكاء الاصطناعي

These frameworks address the AI dimension of the Platform directly. Some are voluntary and intentionally non-prescriptive; others are emerging law. We have adopted them substantively because they are the right baseline for an AI product, even where formal external attestation is not yet available.

4.1 NIST AI Risk Management Framework (AI RMF 1.0)

Status: Aligned.
We operate against the four core functions of the NIST AI RMF (Govern, Map, Measure, Manage), including:

  • Documented AI governance ownership and policies
  • Model and dataset inventory
  • Risk assessment for each model and deployment context
  • Evaluation methodology including disagreement metrics, agreement-level thresholds, and ensemble-based reduction of false positives
  • Drift monitoring and incident review for model behavior
  • Red-team and adversarial-evaluation cadence

4.2 ISO/IEC 42001 (AI Management Systems)

Status: Posture under development.
We are tracking ISO/IEC 42001 as the formal AI management-system standard counterpart to 27001. We expect to assess formal certification once our 27001 program is complete.

4.3 ISO/IEC 23894 (AI Risk Management)

Status: Aligned, used as an internal reference.

4.4 EU AI Act

Status: Posture under development consistent with phased application.

We track our obligations under Regulation (EU) 2024/1689 across the phased application timeline:

  • The prohibitions and AI literacy obligations applicable from 2 February 2025
  • The general-purpose AI provider obligations and AI Office governance regime applicable from 2 August 2025
  • The high-risk system and Article 50 transparency obligations applicable from 2 August 2026
  • The extended transition for high-risk systems embedded in regulated products through 2 August 2027

Provider, deployer, importer, distributor classification. We act as a provider of an AI system (the Platform) for the purpose of the Act. Customers act as deployers. Where the Platform is integrated into a regulated product, the regulated-product overlay may apply.

High-risk classification. We are conducting and documenting our analysis of whether and to what extent the Platform falls under Annex III high-risk categories given how customers use it. Where high-risk obligations apply, we will support deployer obligations including human oversight, transparency, and record-keeping.

Article 50 transparency. Outputs that may be used to determine whether content is synthetic or manipulated are provided with the documentation needed for deployers to satisfy their Article 50 transparency obligations to end users.

General-Purpose AI. We are not currently a provider of a general-purpose AI model.

4.5 OECD AI Principles

Status: Aligned.

٥. الوثائق المتاحة للعملاء والمحتملين

Under NDA, we make available:

  • Data Processing Addendum, with Standard Contractual Clauses and the UK Addendum where applicable
  • Sub-processor list with material-change notification commitments
  • Transfer Impact Assessment template and supplementary measures documentation
  • Penetration test summary letters
  • Security questionnaire responses (SIG Lite, SIG Core, CAIQ)
  • ISMS scope and Statement of Applicability (when ISO 27001 certification is issued)
  • SOC 2 Type II report (when issued)
  • Incident response plan summary
  • Business continuity and disaster recovery summary
  • AI model documentation and evaluation methodology summary
  • EU AI Act provider/deployer responsibility matrix

٦. بيان الوضع الصادق

To restate the rule we apply to ourselves: we do not represent that we hold a certification, attestation, or alignment we do not in fact hold. SOC 2 Type II and ISO/IEC 27001 are in progress. EU AI Act compliance is a forward-looking program keyed to the Act’s phased application dates. Everything described as “operational” is operational today, with controls in place to support it.

If you need a status update beyond what is on this page, including current readiness percentages, target dates, or evidence under NDA, contact us.

٧. التواصل

Email: legal@falsifind.com (compliance, regulatory, and contract questions)
Email: privacy@falsifind.com (privacy and data protection)
Email: security@falsifind.com (security and incident response)
Mail:
Obscurae Intelligence Inc.
Attn: Compliance
522 West Riverside Ave., #8054
Spokane, WA 99201
United States

FalsiFind is a product of Obscurae Intelligence Inc., a Delaware corporation.