Compliance Tools
⚠️ Autional is NOT certified for any compliance framework.
The tools described on this page help you manage compliance workflows within your organization. They are not certifications held by Autional. Achieving certification requires organization-specific policies, controls, and third-party audits. Do not rely on these tools alone for compliance.
Autional includes built-in data models and workflow tooling that support 8 compliance frameworks. These are designed to help your organization manage compliance processes — they are not certifications themselves.
Built-In Compliance Tooling
| Framework | Built-In Support |
|---|---|
| GDPR | DSAR request management, 7-service erasure orchestration, consent audit trail |
| SOC 2 | Audit trail, access control tracking, incident management |
| ISO 27001 | ISMS control register, risk assessment workflow |
| PCI DSS | Control evidence management, access logging |
| HIPAA | PHI access tracking, breach notification workflow |
| Dengbao 2.0 | Chinese security control management, SM cryptography |
Key Technical Features
Hash-Chain Audit Logs
Every authentication event is recorded in a Merkle hash chain. The integrity of the chain can be cryptographically verified. This provides tamper-proof evidence for auditors.
Data Retention
Configurable retention policies per data type. Scheduled archival and cleanup jobs. Audit logs can be retained indefinitely.
Data Classification
4 classification levels built into the API layer: Public, Internal, Confidential, Restricted.