Straits Industriesproduction
Search models, nodes, traces…⌘K
SI

Compliance

15 controls mapped

Controls and evidence organized around the NIST Generative AI Profile functions — govern, map, measure, manage (memo §14.5). Every row points at product evidence that exists in this build; customer-specific legal requirements remain the customer's responsibility.

GOVERN
4controls
MAP
3controls
MEASURE
4controls
MANAGE
4controls
GOVERNPolicies, accountability and supply-chain terms that bound what the fabric may do.
MAPContext: which models, providers, egress paths and data classes are in scope for each request.
MEASUREQuantified evidence — evaluations, guardrail findings, ledgered usage, cost and error taxonomy.
MANAGEOperational response: routing controls, circuits, quarantine, budgets and evidence export.

Control map

NIST GenAI Profile function → the concrete mechanism in this fabric → live evidence you can open.

FunctionControlLive evidenceEvidence pointers
GOVERNGV-1.1
Policies bound model, region and egress choice

Every request resolves a ServiceProfile whose RoutePolicy hard-filters providers, regions, trust tier, ZDR and maximum data classification before scoring.

12 profiles · 5 route policiesService profilesRouting policies
GOVERNGV-2.1
Accountability: one generation ledger

Principal, project, profile, policy snapshot, route plan, attempts, usage and cost are recorded on a single generation record — the join point across security, operations and finance (memo §14.1).

130 generations ledgeredGeneration ledgerAudit & evidence
GOVERNGV-6.1
Supply-chain terms are authorized supply only

Routable supply is provider APIs, cloud service identities and provisioned capacity under contract. Named-user subscriptions are never converted into shared API credentials (memo §2.4, §6.4).

8/8 accounts authorizedTerms table (below)GET /api/admin/terms
GOVERNGV-4.2
Separation of duties on operator actions

Admin mutations require the platform-admin principal plus a step-up assertion (X-Fabric-Step-Up); every action writes an AdministrativeAuditEvent (memo §16.6, §20.1).

step-up enforced on all /api/admin mutationsGET /api/admin/eventsSettings & keys
MAPMP-1.1
Model inventory with lifecycle state

Canonical models carry capabilities, context window, lifecycle (approved/testing/restricted/deprecated/blocked) and per-task-family quality scores; non-approved models are filtered out of candidacy.

13 models · 1 not fully approvedModel catalogGET /v1/models
MAPMP-2.3
Data classification drives the route

The task signature derives a risk level per request; route policies cap the data class they accept and can force ZDR endpoints and Tier A/B egress for confidential traffic.

13 ZDR endpoints availableRoute simulatorRouting policies
MAPMP-3.4
Egress path and trust tier are explicit

Every attempt names the provider account and the egress node that carried it; nodes carry a trust tier from enrollment and a health score from heartbeats (memo §12.4).

7 nodes · 1 quarantinedEgress networkProviders & accounts
MEASUREMS-1.1
Quality evidence is versioned and staged

Golden datasets are replayed through the real pipeline into versioned scorecards; catalog quality scores change only via a rollout that reaches full (shadow → canary → full, memo §7.6).

scorecards + staged rolloutsEvaluationsGET /api/fabric/evaluations
MEASUREMS-2.7
Guardrail findings are recorded per stage

PRE_ROUTE / PRE_MODEL / POST_MODEL / PRE_RETURN decisions (allow, flag, redact, block, require_approval, restrict_route) are attached to the generation and never bypassed by cache or fallback (memo §10.7).

493 decisions · 2 blocked generationsGuardrails & DLPBlocked generations
MEASUREMS-3.2
Errors use one canonical taxonomy

Provider failures are normalized into a single FabricErrorClass union, which drives the fallback graph, circuit breakers and incident fingerprints rather than provider-specific strings (memo §9.1).

4 generations carry an error classIncidentsError search
MEASUREMS-4.2
User feedback is joined to generations

POST /v1/feedback attaches a ±1 rating and optional comment to a ledgered generation, feeding the runtime evidence layer alongside retries, JSON validity and latency.

runtime evidence layer activeFeedback feed
MANAGEMG-2.2
Unsafe output never silently degrades

A safety or DLP block terminates the request — it is never retried on another model — and only output-approved content is written to cache (memo §8.4, §10.7).

invariant enforced in pipelineCacheGuardrails & DLP
MANAGEMG-3.1
Degradation is contained

Per-provider / account / node circuit breakers, retry budgets and an error-conditioned fallback graph remove failing supply from candidacy; operators can open or reset a circuit and drain or quarantine a node.

2 circuits currently trippedIncidents & circuitsEgress network
MANAGEMG-4.1
Spend is bounded before dispatch

Hierarchical budgets reserve estimated cost before the provider call and settle actuals afterwards; a request exceeding the profile ceiling is rejected with budget_exceeded (memo §15.2).

5 budgets enforcedBudgets & FinOps
MANAGEMG-4.3
Evidence is exportable and tamper-evident

Evidence bundles carry the generation, its full timeline, the policy versions in force and a SHA-256 hash chain over the audit events, so any alteration breaks every subsequent link (memo §14.3.6).

bundle export available per generationAudit & evidence exportGET /api/admin/export/evidence

Content capture inventory

Memo §14.2 capture modes derived from each service profile's audit mode. The mode decides what the audit store keeps — hashes only, redacted text, or encrypted full content.

metadata-only
Hashes, counts, policy, route, usage, cost and error data.
Profiles with auditMode = metadata.
in use · 9 profiles
redacted-content
Prompts and responses after configured PII/secret removal.
Profiles with auditMode = redacted; masking runs through the DLP evaluators.
in use · 2 profiles
encrypted-content
Full encrypted input, output, tools and artifacts.
Profiles with auditMode = full; this core stores a ciphertext placeholder (demo KMS).
in use · 1 profiles
customer-managed-content
Full content encrypted under a tenant-controlled key.
Requires tenant KMS integration — deployment-mode feature (memo §19.2).
not enabled
strict-no-retention
No persistent content; metadata and cryptographic hashes only.
Reachable today by pairing metadata capture with a ZDR route policy.
not enabled
legal-hold
Immutable retention override with access and export controls.
Export path exists (evidence bundles); object-lock retention is a persistence-plane concern.
not enabled

Supply policy & terms

Routable supply uses provider APIs, cloud service identities, provisioned capacity and contractually approved credentials only (memo §2.4). Named-user product subscriptions remain named-user entitlements and are never converted into shared API credentials (memo §6.4). Internal plans may present fixed monthly allocations while the underlying supply remains authorized API or provisioned capacity (memo §6.4).

8/8 authorized
AccountProviderPool / regionContractStatusAuthorizedTerms note
acct_bedrock_prod_apse1Amazon Bedrockprod · ap-southeast-1provisionedct_bedrock_provisionedactiveyes

Provisioned/dedicated capacity — contractually reserved throughput; routable within the reservation terms.

acct_anthropic_ent_apse1Anthropicenterprise · ap-southeast-1committedct_anthropic_committedactiveyes

Committed-spend API contract — provider-authorized shared organizational use; drawdown tracked against the commitment.

acct_anthropic_ent_use1Anthropicenterprise · us-east-1committedct_anthropic_committedactiveyes

Committed-spend API contract — provider-authorized shared organizational use; drawdown tracked against the commitment.

acct_vertex_prod_euw1Google Vertex AIprod · eu-west-1meteredct_vertex_meteredactiveyes

Metered API contract — provider-authorized programmatic capacity; routable supply per published API/business terms.

acct_openai_pool_a_euw1OpenAIpool-a · eu-west-1meteredct_openai_meteredactiveyes

Metered API contract — provider-authorized programmatic capacity; routable supply per published API/business terms. OpenAI business terms restrict shared account access, API-key transfer and limit circumvention; this supply is a direct API contract, not a named-user seat.

acct_openai_pool_a_use1OpenAIpool-a · us-east-1meteredct_openai_meteredactiveyes

Metered API contract — provider-authorized programmatic capacity; routable supply per published API/business terms. OpenAI business terms restrict shared account access, API-key transfer and limit circumvention; this supply is a direct API contract, not a named-user seat.

acct_openai_pool_b_apse1OpenAIpool-b · ap-southeast-1meteredct_openai_meteredactiveyes

Metered API contract — provider-authorized programmatic capacity; routable supply per published API/business terms. OpenAI business terms restrict shared account access, API-key transfer and limit circumvention; this supply is a direct API contract, not a named-user seat.

acct_vllm_sg_01Self-hosted vLLMonprem · ap-southeast-1provisionedct_vllm_internalactiveyes

Provisioned/dedicated capacity — contractually reserved throughput; routable within the reservation terms.