Skip to main content

Compliance Evidence

The following mappings connect Zen Mesh technical features to compliance framework controls. Each mapping uses the relationship "supports" or "maps_to" — none claim certification, authorization, or formal compliance.

Important: Zen Mesh is not PCI compliant, not HIPAA compliant, not FedRAMP authorized, not SOC 2 certified, and not ISO certified. These mappings describe technical capability support, not compliance status.

Feature-to-Control Graph

FeatureSecurity PropertyFrameworkControlRelationshipEvidence
HMAC payload signingIntegrityPCI-DSS v4.04.2.1supportsTRUST-PROOF-003
HMAC payload signingIntegrityNIST SP 800-53SC-8supportsTRUST-PROOF-003
HMAC payload signingIntegrityNIST SP 800-53SC-13supportsTRUST-PROOF-003
HMAC payload signingIntegritySOC2 TSCCC6.xmaps_toTRUST-PROOF-003
mTLS cert rejectionAuthenticated transportNIST SP 800-53SC-8supportsTRUST-PROOF-006
mTLS cert rejectionAuthenticated transportNIST SP 800-53SC-23supportsTRUST-PROOF-006
mTLS cert rejectionAuthenticated transportISO 27001:2022A.8.24maps_toTRUST-PROOF-006
Enrollment rejectionAccess controlNIST SP 800-53IA-2supportsTRUST-PROOF-001,002
Enrollment rejectionAccess controlNIST SP 800-53AC-3supportsTRUST-PROOF-001,002
Enrollment rejectionAccess controlSOC2 TSCCC6.1maps_toTRUST-PROOF-001,002
ZenLock ciphertextSecret managementNIST SP 800-53SC-12supportsTRUST-PROOF-005
ZenLock ciphertextSecret managementNIST SP 800-53SC-13supportsTRUST-PROOF-005
ZenLock ciphertextSecret managementISO 27001:2022A.10.1maps_toTRUST-PROOF-005
Evidence ledger/MerkleAudit trailSOC2 TSCCC3.xmaps_toRuntime evidence pack
Evidence ledger/MerkleAudit trailNIST SP 800-53AU-2supportsRuntime evidence pack
FailoverResilienceNIST SP 800-53CP-2maps_toPROOF-009
DLQ/retryError handlingNIST SP 800-53SI-4maps_toPROOF-003
TLS 1.3 transportEncryption in transitPCI-DSS v4.04.2.1supportsImplementation
mTLS workload identityAuthenticationNIST SP 800-53IA-5supportsTRUST-PROOF-004

Full Machine-Readable Map

The complete compliance graph is available at:

/ai/evidence/v1/compliance-map.json

Each entry includes framework, control_id, control_title, relationship, claim_status, evidence_refs, and a disclaimer note.

Framework Coverage

FrameworkMapped Controls
NIST SP 800-53 Rev5AC-3, AU-2, CP-2, IA-2, IA-5, SC-8, SC-12, SC-13, SC-23, SI-4
SOC2 TSC (2023)CC3.x, CC6.x, CC6.1, CC7.x
ISO/IEC 27001:2022A.8.24, A.10.1
PCI-DSS v4.04.2.1
HIPAA Security Rule§164.312(a)(1) (access control), §164.312(e)(1) (transmission security) — mapped as supports only

Non-Claims

  • Not PCI compliant or validated
  • Not HIPAA compliant or BAA-covered
  • Not FedRAMP authorized
  • Not SOC 2 certified or audited
  • Not ISO certified
  • Mappings are technical capability indications only
  • Evidence is local/mock only unless stated otherwise