generated: '2026-08-13' method: searched source: >- https://edgelabs.ai/platform/compliance-center, https://edgelabs.ai/llms.txt, https://scalarr.io/document/, https://github.com/agent-defense/parallax (docs/RULES.md, rules/), and live probes of portal.edgelabs.ai note: >- A hard distinction runs through this file. AI EdgeLabs SELLS compliance tracking — its Compliance Center ships NIS2 and CRA control mappings as a product feature — but Scalarr Inc. publishes no certification, audit report or trust center of its OWN. Those are different claims and are recorded separately. For that reason no `Compliance` pointer is emitted in apis.yml: the compliance_published check asserts the company's own compliance posture, which Scalarr does not publish. standards: - id: rfc9116 name: security.txt conforms: true partial: true evidence: >- https://portal.edgelabs.ai/.well-known/security.txt returns 200 text/plain with Contact and Expires fields. The Expires value (2025-12-01) is in the past, so the file is stale under RFC 9116 §2.5.5, and it is served from the portal host only — the apex hosts 404. - id: rfc9457 name: Problem Details for HTTP APIs conforms: false evidence: >- The portal API returns a vendor envelope {"message","status","errorCode","title"} as application/json, not application/problem+json. Parallax returns {"error": "..."}. - id: semver name: Semantic Versioning conforms: true partial: true evidence: >- Parallax releases follow MAJOR.MINOR.PATCH, but tags from 0.4.0 onward use an irregular `v.0.6.0` prefix that standard semver tooling will not parse. - id: oauth2 name: OAuth 2.0 conforms: partial evidence: >- The AI EdgeLabs console federates sign-in through Google and GitHub OAuth (authorize URL and userinfo scopes present in the portal bundle). Scalarr is an OAuth CLIENT here, not an authorization server — it publishes no /.well-known/oauth-authorization-server document and no scope reference, so third-party API authorization is not offered. - id: oidc name: OpenID Connect conforms: false evidence: >- https://portal.edgelabs.ai/.well-known/openid-configuration returns the SPA HTML shell, not a discovery document. - id: sigma name: Sigma detection rule format conforms: true evidence: >- Parallax ships a Sigma evaluator that loads multi-document Sigma YAML, with 14 Sigma rules promoted to stable in 0.6.0 (rules/sigma/*.yaml). - id: cel name: Common Expression Language conforms: partial evidence: >- Parallax implements a CEL-LIKE expression evaluator (==, !=, &&, .contains(), .startsWith(), .matches()) — the README describes it as CEL-like, not a conformant CEL implementation. - id: ebpf name: eBPF / Falco runtime instrumentation conforms: true evidence: >- The AI EdgeLabs sensor installer pins FALCO_VERSION=0.43.0 and enforces minimum kernel versions for BPF (4.14 x86_64 / 4.17 aarch64, 5.8 for modern BPF), confirming eBPF-based collection. source: https://static.edgelabs.ai/agent-install.sh - id: apache-2.0 name: Apache License 2.0 conforms: true evidence: Parallax is Apache-2.0 licensed (LICENSE + Cargo.toml). regulatory_product_mappings: note: >- Regimes the AI EdgeLabs PRODUCT maps controls for. These are capabilities sold to customers, NOT certifications held by Scalarr Inc. shipped: - id: nis2 name: EU NIS2 Directive claim: >- "Compliance Center ships with out-of-the-box control mapping" for NIS2 — EU network and information security requirements for essential and important entities. source: https://edgelabs.ai/platform/compliance-center - id: cra name: EU Cyber Resilience Act claim: >- Out-of-the-box control mapping for the CRA — secure-by-design lifecycle requirements for products with digital elements. source: https://edgelabs.ai/platform/compliance-center roadmap: - HIPAA - ISO/IEC 62443 - PCI DSS - NIST own_compliance_posture: certifications: [] trust_center: false audit_reports: [] legal_documents: - name: Services Agreement url: https://scalarr.io/document/services_agreement/ - name: Privacy Policy url: https://scalarr.io/document/scalarr-privacy-policy/ - name: Data Processing Agreement url: https://scalarr.io/document/dpa/ - name: CCPA notice url: https://scalarr.io/document/ccpa/ - name: Cookie Policy url: https://scalarr.io/document/cookie-policy/ - name: Privacy Shield Policy url: https://scalarr.io/document/privacy-shield-policy/ note: >- The EU-US Privacy Shield framework was invalidated by Schrems II in 2020 and superseded by the EU-US Data Privacy Framework in 2023. This page is still published on the legacy Scalarr domain. - name: Terms and Conditions (AI EdgeLabs) url: https://edgelabs.ai/terms-and-conditions - name: Privacy Notice (AI EdgeLabs) url: https://edgelabs.ai/privacy-notice note: >- No SOC 2, ISO 27001, PCI DSS, HIPAA or FedRAMP claim appears on any Scalarr or AI EdgeLabs page, and no trust center exists at trust.edgelabs.ai (does not resolve). The published documents are legal/privacy terms, not an attested compliance program — which is why no Compliance or TrustCenter pointer is emitted. summary: standards_checked: 9 conformant: 5 partial: 3 non_conformant: 2 own_certifications: 0