Compliance becomes an execution capability
The Compliance & Trust Engine now evaluates signed identity and environment trust, tenant policy, provider eligibility and sensitive-data signals at the Router boundary.
What changed
- Request-bound Trust Context assertions with replay protection
- Versioned policy-as-code and explainable decision evidence
- Reviewed Provider Trust profiles for 11 production integrations
- Input and output inspection for regulated and secret data classes
- Content-free tenant posture and route-simulation APIs
- Sydney multi-AZ shadow rollout with a proven rollback path
SHADOWShadow mode records the decision that enforce mode would make. It does not deny customer traffic.
