Compliance & Audit
How can an auditor validate the integrity of the Catalyst execution engine itself?
Catalyst's control plane emits signed attestations covering build provenance and runtime integrity, giving auditors a verifiable baseline. This leverages software supply chain provenance data and runtime monitoring to prove the engine has not been tampered with. Mechanism: An in-toto-style chain links build manifests, source code hashes, and deployment measurements. Caveat: The auditor must trust Diagrid's signing key and the cloud provider's hardware attestation; physical tampering is not detectable.
Was this article helpful?
Your feedback helps improve Diagrid's FAQ experience.
Keep reading
More Diagrid FAQ articles
- Compliance & Audit
What evidence artifacts should I gather from an AI agent platform for an audit of automated decision-making?
An AI agent platform provides verifiable step records and identity bindings as foundational audit evidence, though business rule correctness remains external.
- Compliance & Audit
How does the platform capture human-in-the-loop interventions for regulated workflows that require manual approval?
Durable execution suspends agents for human input, recording reviewer identity and decisions as signed steps for an unalterable compliance record.
- Compliance & Audit
Can I control where agent state and execution records are stored to comply with data residency requirements?
Region-specific deployment options ensure durable execution state and step payloads remain within geographic boundaries to meet localization mandates.