Compliance Reports

Per-report compliance and audit reports across 6 frameworks plus 4 ledger-derived kinds. Pay-as-you-go (PAYG); tier-agnostic — same price for Pro, Pro Fast, Enterprise, Enterprise Fast, and pay-as-you-go. Settle in USDC.e on COTI V2 mainnet (canonical, no premium).

Stage: stub. This page lists the 10 SKUs available and 11 example outputs. The report-generation engine is in implementation. Wallet-connect, per-report dispatch, and live PDF/A-3 examples land when the report engine ships.

Available report kinds

Report kind Framework or source Per-report price (USD) Brief description Status
Compliance attestation GDPR Art.15 (subject access response) $2,400 11 of 12 fields per Art.15(1)+(2); commonly used electronic form. Sample — engine in progress
Compliance attestation GDPR Art.17 (erasure response) $1,500 11 fields per Art.17 + Art.12+19; concise format. Sample — engine in progress
Compliance attestation SOC 2 Type 1 $20,000 19 fields per AICPA TSC + DC-200; restricted-use format. Sample — engine in progress
Compliance attestation SOC 2 Type 2 $50,000 21 fields per AICPA TSC + DC-200; restricted-use format. Sample — engine in progress
Compliance attestation ISO 27001 $25,000 31 fields per ISO/IEC 27001:2022 Clause 7.5; 9 conditional on Annex A scope. Sample — engine in progress
Compliance attestation AML / FinCRA $4,000 168 fields per FATF R.16 + 31 CFR §1010 + FinCEN SAR/CTR; Part IV items 71-77 deferred to v2. Sample — engine in progress
Audit export GC-14 receipt history per scope $50 Per-tenant audit ledger; PDF/A-3 with embedded JSON per ISO 19005-3. Sample — engine in progress
Billing history Cashier audit-ledger query $25 Per-tenant payment history over a specified time window (max 1 year). Sample — engine in progress
Bespoke template Operator-uploaded; schema-bounded $6,000 Operator-defined projection from the 262-field universe; max 200 fields per template (configurable per operator). Sample — engine in progress
Registry attestation Public proof-of-existence $0 (free) Public-record attestation of agent or cell registration. No authentication required; rate-limited 1000/hr per IP with CAPTCHA on exceed. Sample — engine in progress

Erasure confirmation (GDPR Art.17 4-step proof) is a scope-subset of GDPR Art.17 attestation; same $1,500 price. Engine verifies GC-3 destroyDek + GC-4 tombstone + GC-5 CID-blacklist + post-forget recall returning “no memories stored”.

Authorization paths

Four authorization paths, each emitting a GC-14 audit receipt with the full chain:

  • Public — registry-attestation only; anyone can request; output contains only public-record fields.
  • Self — agent or wallet-owner generates own report. Web: EIP-712 wallet-sig over fresh challenge nonce (replay window 30 min). MCP: ML-DSA signature by the requesting agent's identity.
  • Operator self — operator pulls reports about their own MCP-instance scope (operator-customer-list, operator audit history). ML-DSA signature.
  • Operator for downstream — operator pulls reports about a downstream customer; two-of-two authorization required: operator's ML-DSA signature plus either a downstream-customer-signed access grant or legal-basis evidence (subpoena hash + jurisdiction + public-record URL).

Operator-ToS obligation: operators using operator-for-downstream paths disclose to their customers in their own ToS that reports may be pulled. SAIHM provides audit-trail integrity; operator owns ToS clarity. The GC-14 audit chain is the post-hoc accountability mechanism.

Examples

Stage: stub. 11 anonymized synthetic PDF/A-3 example documents will land when the report engine ships. Each will be linked here for download.

# Example Source kind Framework param
1example-gdpr-art-15.pdfCompliance attestationgdpr-art-15
2example-gdpr-art-17.pdfCompliance attestationgdpr-art-17
3example-soc2-t1.pdfCompliance attestationsoc2-t1
4example-soc2-t2.pdfCompliance attestationsoc2-t2
5example-iso27001.pdfCompliance attestationiso27001
6example-aml.pdfCompliance attestationaml
7example-audit-export.pdfAudit export
8example-erasure-confirmation.pdfErasure confirmation
9example-billing-history.pdfBilling history
10example-bespoke.pdfBespoke templatee.g., AML+GDPR fintech hybrid
11example-registry-attestation.pdfRegistry attestation

Synthetic example data: fully fabricated agent IDs, redacted financial values, public-domain placeholder narrative content, no internal-only fields. Synthetic cellId hashes follow 0x000…example pattern.

Format and integrity

Default format: PDF/A-3 (ISO 19005-3) archival, with embedded source data per spec, XMP metadata, and ICC color profile. Alternative formats: JSON or CSV (per request). Every report bundle is signed with the engine’s GC-14 receipt seal. Receipts are retained per the registry-cell-protection policy (at least 17 months for any cited receipt).

Caps: time-window per query 1 year, result-size per report 50 MB, field-projections per template 200, customer-IDs per scope 10,000. Per-operator rate-limit defaults to 100 reports/hour; per-customer-ID rate-limit defaults to 10 reports/hour. Soft-cap behavior: escalate-on-exceed with operator notification and GC-14 receipt.

Disclosure

These prices apply to compliance reports generated directly via SAIHM. Independent developers building on SAIHM may publish lower prices, additional report kinds, or bespoke templates.

Snapshot

Prices above are the snapshot effective 2026-05-07. Engine implementation in progress; the report-engine completion date will be communicated separately.