Skip to content
The Platform

Five phases. Provable compliance.
Cryptographic audit trail.

SpanForge is the AI compliance platform for every team — structured around RFC-0001 SpanForge, the open event-schema standard for AI governance. Each phase has defined compliance obligations, auditable exit gates, and evidence that satisfies EU AI Act, GDPR, SOC 2, ISO 42001, and NIST AI RMF.

Comply. Prove. Scale.

Governance layer

The T.R.U.S.T. Framework

Every SpanForge-certified AI system satisfies five dimensions of responsible deployment. The T.R.U.S.T. Framework is not a checklist — it is the governance standard operationalised as technical controls, regulatory evidence packages, and cryptographically signed audit trails.

Explore the Framework →
T

Transparency

Customers, regulators, and employees understand how AI affects them. AI behaviour is made intelligible to all affected parties — not just technical teams.

R

Responsibility

A named human is accountable for every AI system. AI cannot be deployed without a designated owner who carries accountability for its behaviour in production. Responsibility extends to cost: the Cost Intelligence Layer makes infrastructure spend visible at Design time and measures actual token costs in production via the SpanForge llm.cost.* namespace — ensuring accountable owners understand the financial implications before committing to them.

U

User Rights

Consent, transparency, and recourse for every individual AI affects. Users have the right to understand how AI decisions affect them and to seek redress where required.

S

Safety Guardrails

Technical constraints embedded in architecture, not just policy. Safety mechanisms are built into the system — not left as aspirational guidance or documents.

T

Traceability

Every AI decision must be traceable to its source data, model version, and configuration state. Full audit trail. No black boxes. Every decision is logged with an immutable, timestamped, cryptographically signed record — ready for regulators, auditors, and post-incident review.

Start with your compliance baseline.

Not sure where you stand against EU AI Act, GDPR, or SOC 2? The Discover phase maps your obligations before you commit to architecture.

Start with Discover →