EVALUATION CONTROLS • RELEASE-DISABLED

One platform.
A transparent regulated-controls roadmap.

Explore candidate controls below. Regulated modes remain disabled until their documented acceptance gate passes; this page is not a certification or compliance claim.

CONTROL DESIGN EXPLORER
Choose a mode — watch the mandatory controls light up
Approval workflow required
Financial category guard
7-year retention minimum
Dual-control / threshold support
Segregated roles (RBAC)
Rules enforced by the platform's compliance enforcement layer (documented in the architecture specs). Applied on create/send/sign. Org lock is irrevocable without super-admin.
CROSS-BORDER DETECTION TOOL
Simulate signer locations + document type
TRANSFER WARNING — enforce SCC + explicit consent timestamp + 10y+ retention for this route
Enforcement is automatic when mode is locked. See cross-border and retention logic in the compliance enforcement layer (documented in deployment and security specs).
RETENTION MATRIX — ENFORCED MINIMUMS
MODEMIN YEARSTRIGGERS / NOTES
STANDARD5yESIGN baseline
HIPAA10yBAA + encryption
SOX7yFinancial + approvals
FDA_21CFR1120yLTV/OCSP + reason
Click a row to highlight. Retention purge job respects these per-mode minima. Audit logs kept for full period.
Lock prevents downgrade
Once org.complianceModeLocked = true, only a privileged action can change it. Every agreement creation validates against the locked mode. Drift becomes impossible.
org compliance enforcement functions (documented in security specs)
Evidence you can hand a regulator
Mode, lock status, and every enforcement decision are themselves events in the hash chain. The public verifier shows the compliance context at signing time.
See PKI + public verify architecture →
FlySign | E-signatures with cryptographically verifiable audit trails