# AIGovernr public due-diligence pack

Verified: 2026-08-06. Next review: 2026-09-06.

This public index contains no secrets or customer data. All implemented product facts are Beta; the public developer API is Planned. No independent certification, customer count, aggregate rating, uptime percentage, regional deployment or customer-managed-key claim is made.

## CAP-PUBLIC-SCAN

Beta. Anonymous website AI compliance scan. Production-like rate-limit, retention and cross-tenant exercises remain pending.

## CAP-GOV-WORKSPACE

Beta. Multi-persona governance workspace. Production-like identity, notification and concurrency proof remains pending.

## CAP-FRAMEWORK-GRAPH

Beta. Versioned framework and obligation graph. Coverage is mapped published obligations divided by total published obligations and does not imply certification.

## CAP-GOV-COPILOT

Beta. Permission-aware governance copilot. Extractive grounded answers, citations, abstention, draft-only actions and feedback are implemented; production evaluation remains pending.

## CAP-CONNECTORS

Beta. Governed connector ingestion. Live provider retry and operational exercises remain pending.

## CAP-ENTERPRISE-ID

Beta. OIDC/SAML/SCIM controls. SAML is configuration-only; real IdP login/rollover and SCIM production proof remain pending.

## CAP-REGIONAL-DATA

Beta. Regional policy, retention and key lifecycle controls. Physical regional hosting, CMK and backup restoration proof remain pending. Private/on-premises deployment is unsupported.

## CAP-PUBLIC-API

Planned. No supported public developer API or SLA has been released.

## CAP-CLI

Planned. CLI and CI documentation is a roadmap preview; no supported developer-tool release is claimed.

## Assurance boundaries

- Independent certifications: none claimed.
- Verified public availability history: none published.
- Public subprocessor list: pending contractual verification.
- Security architecture controls: self-attested repository implementation, not independent assurance.
- Production-like end-to-end persona, restore and external integration evidence: pending.

Contact the product/security owner through the published contact and vulnerability-disclosure channels for current contractual evidence.
