← TrustAI

Compliance & Security

TrustAI is built on Knox Blockchain — a 13-layer security and compliance architecture aligned with NIST SP 800-53, HIPAA, FedRAMP, SOC 2, and OMB Circular A-123. Trust, estate, and fiduciary disputes involve protected health information, financial records, and minor children — TrustAI treats every byte accordingly.

Operator: Bonis Systems LLC UEI: R2BPJDC5CBA3 USPTO Patent Pending #64/036,498

Knox Blockchain — 13 Security Layers

#LayerStatus
1DDoS Protection (50 req/10s sustained, 20/2s burst)Active
2Bot & Scanner Detection (16 signatures)Active
3Payload Inspection (XSS, SQLi, traversal, injection)Active
4Honeypot Traps (15 decoy paths)Active
5Brute Force Prevention (lockout at 5 attempts)Active
6IP Threat Scoring & Auto-Block (score 80+)Active
7Content Security Policy (CSP)Active
8HSTS + Security HeadersActive
9Request Fingerprinting (SHA-256)Active
10Knox Blockchain Audit Trail (immutable)Active
11AES-256-GCM Encryption at RestActive
12TLS 1.3 Transport SecurityActive
13Permissions-Policy (camera, mic, geo, payment disabled)Active

PII / PHI Protection

TrustAI's PII scrubber automatically detects and redacts the 18 HIPAA Safe Harbor identifiers plus legal/financial data before any AI inference, log write, or external transmission:

IdentifierDetectionTreatment
Social Security NumberRegex (validated)Redacted
Employer ID NumberRegexRedacted
Bank account / routingPattern + contextRedacted
Medical Record NumberPattern + contextRedacted
Date of birthRegexRedacted
Phone, email, ZIP, IPRegexRedacted
Driver licenseRegexRedacted
Credit cardLuhn + regexRedacted

NIST SP 800-53 Rev 5 Control Families

FamilyDescriptionStatus
ACAccess Control (RBAC, session management)Implemented
AUAudit & Accountability (immutable Knox ledger)Implemented
IAIdentification & Authentication (bcrypt 12 rounds)Implemented
SCSystem & Communications Protection (TLS 1.3, AES-256)Implemented
SISystem & Information Integrity (payload inspection, PII scrub)Implemented
IRIncident Response (Knox dashboard, threat log)Implemented
CMConfiguration Management (Cloud Run revisions)Implemented

HIPAA Alignment

While trust documents are not Protected Health Information per se, they routinely contain medical history, capacity assessments, and HEMS distribution evidence. TrustAI applies HIPAA Security Rule administrative, physical, and technical safeguards to all case data. A signed Business Associate Agreement (BAA) is available to any covered entity engagement: View BAA template.

Federal Compliance Posture

FrameworkStatus
FedRAMP Moderate (target)Readiness Assessment in Progress
SOC 2 Type IISelf-Assessment Complete; Formal Audit Pending
FISMA Continuous MonitoringActive (Knox Dashboard)
OMB Circular A-123Compliant (immutable audit trail)
Federal Records ActCompliant (blockchain retention)
Section 508 AccessibilityAudit Scheduled

Hosting Infrastructure

Google Cloud Run (us-central1) on a FedRAMP High authorized cloud platform. Encryption at rest via Google-managed AES-256-GCM. TLS 1.3 with HSTS preload. Inherited GCP infrastructure controls.

Machine-Readable Attestation

For federal auditors and procurement officers: /api/knox/compliance returns a JSON attestation of platform compliance posture, security controls, and Knox Blockchain configuration.

Attestation generated by Bonis Systems LLC. UEI R2BPJDC5CBA3. Contact: jonisfields@gmail.com.