Trust & compliance posture

What you can check.
What is still in progress.

Where Roam stands on SOC 2 Type II (target Q1 2027), ISO/IEC 42001 (target Q3 2027), EU AI Act Article 12 record-keeping, and the NIST AI Risk Management Framework — plus the DPA, sub-processor list, security contact, vulnerability disclosure, and data-flow diagram we hand over today. Evidence support and control mapping. Not certification.

Built in Athens · Made in the EU · Apache 2.0 CLI · Local source analysis · No API key · No automatic source-code or telemetry upload · Evidence hash-verifies offline · No analytics · No cookies

Where we are today

Four frameworks procurement teams ask about, with our actual status and roadmap. No current independent attestation against any of these; when that changes we will publish the auditor or certification-body name and the report excerpts directly on this page.

SOC 2 Type II — in design (target Q1 2027) Controls in design. Honest target window: Q1 2027 for the first Type II report. No current independent attestation; the window is planning guidance, not a commitment. We will publish the auditor name and report excerpts here when issued.
ISO/IEC 42001 — gap analysis (target Q3 2027) AI management system gap assessment in progress against the ISO/IEC 42001:2023 control set. Honest target window: Q3 2027 for certificate issue. No current certification; the window is planning guidance, not a commitment.
EU AI Act — record-keeping inputs Roam can supply records of collected development checks for a broader governance review. Those records are not the operational logs of a deployed AI system and do not establish that Article 12 requirements are met. Your counsel and auditors determine applicability and the evidence your system needs.
NIST AI RMF — voluntary frame The NIST AI Risk Management Framework 1.0 (Jan 2023) is a voluntary framework. We map Roam's evidence outputs to the MAP / MEASURE / MANAGE / GOVERN categories so customers without a mandated regime can still anchor their AI-agent change-control program to a recognized reference.

See the governance page control mapping for the row-by-row table tying each evidence type to the SOC 2, ISO 42001, NIST AI RMF, and EU AI Act Article 12 clauses it supports.

What we have right now

Artifacts a procurement reviewer can collect today, before external attestations exist. All five are public on GitHub or this site; nothing is gated behind a sales conversation.

  1. 1 Data Processing Addendum (DPA). GDPR Article 28 processor agreement covering the customer-as-controller, Roam-as-processor relationship for PR Replay and planned Roam Review engagements. Lists processing categories, retention windows, sub-processor change notice, and audit rights. Published at templates/legal/dpa.md; the PR Replay SOW that incorporates this DPA by reference is at templates/legal/sow-pr-replay.md.
  2. 2 Sub-processor list. PR Replay v1 sub-processors are Stripe (payment processing) and GitHub (only when the buyer chooses GitHub repository access); the full list with purpose and EU/US location is in section 6 of the privacy policy. The DPA requires 14-day advance notice for material additions. The CLI itself has no runtime sub-processors — it runs locally by default, with the explicit network exceptions inventoried below.
  3. 3 Security contact. [email protected] — OpenPGP key auto-published by Proton. Discoverable via the security.txt file at the standard well-known location. Acknowledgement within one business day.
  4. 4 Vulnerability disclosure policy. Full coordinated-disclosure policy on the security page: scope, safe-harbor terms, remediation targets (high within 30 days, medium within 90, low at next scheduled release), and a default 90-day public-disclosure window we extend on reporter request. Roam does not run a monetary bug-bounty program yet; until a paid program is announced, responsible reports receive public acknowledgement in the security page hall-of-fame plus, on request, a written reference confirming the report and remediation outcome.
  5. 5 Data-flow diagram. The CLI's data flow is short enough to inline: your source code is read from the local working tree, parsed and indexed into a local SQLite database under .roam/, and analyzed by local processes. No API key, no automatic source-code upload or telemetry, and no required vendor cloud endpoint — no analytics, no automatic model-training upload, and no listener during ordinary analysis. On first parser use, a cold cache retrieves one checksum-verified platform bundle from the parser dependency's GitHub release and retains it locally; prewarm it before disabling egress. Explicit features can query PyPI/GitHub, probe operator-selected URLs, post metrics or a GitHub check, use keyless Sigstore, summarize selected MCP report snippets with the configured model provider, or open an HTTP listener. They are off unless selected (apart from a missing parser bundle) and are inventoried with payload classes in docs/network-boundary.md. The same default-local, no-automatic-upload stance is contractually committed in DPA §6. Roam Review and Roam Cloud data flows are documented inside the procurement packet.

Roam's evidence layer

The free CLI provides records and checks that reviewers can inspect. They show collected evidence and its gaps, not everything an agent did. They can support a wider review; they do not replace an independent audit or certification.

Collected check results After bundle initialization, full JSON results from supported commands can be collected with their source locations and check status. Earlier commands and commands without auto-logging are not a complete record. Keep partial results and missing checks visible, alongside the project's actual test results.
A bundle for the change roam pr-bundle init starts collection; roam pr-bundle emit --strict checks the preparation bundle for missing required evidence. It is not automatically signed: CodeGraph attestations and signing are separate, explicitly configured paths. Recorded context is not proof of everything the agent consumed or used in its reasoning.
Mode enforcement Four cumulative modes — read_only, safe_edit, migration, autonomous_pr — describe permitted operations. The MCP dispatcher applies the configured mode policy at its tool boundary; this does not contain commands run outside Roam. A lease records a coordination claim, not human approval. Keep required approvals in the project's own review process.
Run ledger with HMAC chain A roam runs session stores HMAC-chained entries. roam runs verify checks their integrity using the local key. Someone with that key can rewrite the chain; it is not independent proof of actor identity, complete collection, or successful work. Preserve the key and records under your project's access controls.

Follow the worked change-review example to see collection, missing evidence, and ledger verification in context. For the full control-mapping table from these four substrates to SOC 2 CC8.1, ISO/IEC 42001 Annex A, NIST AI RMF, and EU AI Act Article 12, see the Agent Governance Evidence Pack page.

Evidence support, not certification This page is evidence support, not a certification claim. Roam Code provides evidence-export and control-mapping support for AI-agent change governance; it does not perform compliance attestation, and nothing here should be read as a statement of formal conformity against any framework. Consult qualified counsel and auditors for formal certification against SOC 2, ISO/IEC 42001, the EU AI Act, or any other regime.
Article 12 framing Article 12 addresses event logging by high-risk AI systems. Roam's repository checks are development records, not a substitute for a deployed system's required logs or human-oversight controls. Consult the regulation and qualified counsel to assess your system.
Timeline candor Honest target windows: SOC 2 Type II Q1 2027, ISO/IEC 42001 Q3 2027. Planning guidance, not a commitment. Once external partners and dates are signed we will publish them here. Procurement reviewers who need a binding date: [email protected]. Payment-side commitments — refund window, invoicing cadence, Stripe-receipt vs legal tax-invoice — on the refund policy and PR Replay audit.
EU-based provider Default PR Replay processing location is disclosed per DPA §11. A separate tax invoice is issued within 30 days of payment according to the applicable VAT treatment. EU B2B reverse charge is applied where applicable; confirm billing details before payment. See the invoice terms, security policy and the procurement packet for the DPA, no-training commitment, and supply-chain posture.
Apache 2.0 open-source engine The CLI that produces every evidence artifact is Apache 2.0 and public on GitHub · the same package distributed on PyPI. No proprietary binary in the analysis pipeline. Reviewers can inspect and rebuild the collection and verification software. Reproducing a recorded bundle also requires its retained inputs and records, including the source revision, tool versions, and configuration. The LICENSE file in the repo carries the canonical Apache-2.0 text.

Need a question answered for an in-flight procurement review, or a redacted DPA reviewed against your standard? Email [email protected] — acknowledgement within one business day.