Educational · Compliance

AI compliance for governed agent platforms

AI compliance is the ability to prove who ran which agent, under which policy, with which spend controls—and to retain evidence your auditors accept. Kimss contributes workspace attribution and optional gateway logging; Azure Policy, Monitor, and your legal program remain essential.

Last updated: July 24, 2026

What “audit-ready” means here

Kimss records product-level attribution—tenants, workspaces, agents, keys, credits—so engineering and finance share one vocabulary during reviews.

Optional Azure API Management diagnostics to Log Analytics can provide immutable gateway logs for Article 12-style discussions when enabled and verified. Do not claim gateway telemetry is active in every deployment—see architecture docs and the APIM E2E requirement.

Formal certifications and attestations are provided under NDA during procurement, not as marketing slogans on public pages.

Controls that support compliance programs

Identity, isolation, retention posture, and change management for agents matter as much as model cards.

  • Entra-backed operator identity and workspace RBAC.
  • Tenant isolation for data assets and agents.
  • Credit pools and exhaustion policies as financial controls.
  • Public security docs: architecture, compliance, trust & safety.
  • Changelog and environment promotion for change evidence.

Honest scope

Kimss does not replace your Azure compliance tooling, DLP, or legal review. It adds the SaaS control plane layer on Foundry.

Read /docs/security_compliance, /docs/trust_safety, and /ai-governance-for-enterprises. Pair Kimss ledgers with Azure Cost Management and Microsoft Purview (or equivalent) as your program requires.

Questionnaire readiness

Point reviewers at public architecture docs first; escalate proprietary attestations through enterprise channels.

Common questions—prompt retention, subprocessors, isolation model, audit sinks—are addressed in public security documentation. Enterprise customers engage /enterprise for deeper evidence packages.

Frequently asked questions

Does Kimss store prompts for training?

Kimss is designed with zero prompt retention where that policy applies to your tier. See /docs/trust_safety for guardrail details.

Is Log Analytics always on?

APIM → Log Analytics is optional and environment-specific. Verify before citing it in a customer security packet.

Where are compliance docs?

/docs/security_compliance and /docs/security_architecture.

How do we start a compliance review?

Share /why-kimss and security docs, run a staging workspace demo, then involve /enterprise for NDA attestations.