Compliance
Where Histor stands against the frameworks buyers ask about. Nothing here is certified; the status says exactly what holds.
| Framework | Status | What that means |
|---|---|---|
| EU AI Act, regulatory sandboxes (Art. 57 to 59) | Built for | Histor's evidence formats and verifier exist to record and check sandbox tests. There is no certification for this; the claim is what the public verifier does. |
| GDPR | Synthetic data only | Runs so far use synthetic and public test data, so no data about test subjects is processed. The control plane does hold participants' staff data (names, work email, sign-in ids). A DPIA and a lawful basis come before any real data. |
| ISO/IEC 27001:2022 | Mapped, not certified | Our controls are mapped to Annex A in the security pack (on request). No certification body has reviewed the mapping, and Histor holds no certificate. |
| SOC 2 | Not held | No SOC 2 report, Type I or II. |
| ISO/IEC 42001 | Not held | No AI management system certification. |
| eIDAS | Not qualified | Timestamps come from FreeTSA, which is not a qualified trust service provider. Plan signatures are not qualified electronic signatures. |
| Cyber Resilience Act | Under review | The open-source release under EUPL-1.2 is likely outside the CRA; a supported commercial distribution would likely be in scope. Needs legal confirmation. |
| Open source | Published | The verifier and the evidence formats are public under EUPL-1.2. The engine follows with the first pilot. |
Controls
What the system does, by area, and how to check it. "Engine code, on request" means the source is not public yet.
Evidence integrity
Every action in a participation, allowed or refused, is written to the ledger before it takes effect, each entry carrying the hash of the one before
In placeCheckThe verifier recomputes the chain; the five altered bundles in examples/tampered must fail
The ledger database refuses UPDATE, DELETE and TRUNCATE on entries, even for its owner; the console may only read and append
In placeCheckTriggers and grants in the engine, published with the first pilot
Entries are timestamped by an external RFC 3161 authority (FreeTSA)
In placeCheckdocs/verifier.md: check timestamps against a root you fetch yourself
In placehistor verifychecks a bundle offline, with no network, no test data and no trust in the operatorCheckRun it on the sample participation with
--network none
Data protection
Model weights are encrypted by the provider and decrypted only in the compute node's memory, for one job
In placeCheckRuns record the weights' digest; the provider keeps the encrypted copy in their own registry
Keys are destroyed at the end of a participation and the destruction is a signed ledger entry the verifier requires
In placeCheckThe
keys_destroyedcheck in docs/verifier.mdThe model receives the test input only: labels, ages, file names and item ids never reach it, and it has no network access
In placeCheckdocs/threat-model.md; each run records how isolation was enforced
Registry pull tokens are kept in a key store (OpenBao); the ledger records only a reference to them
In placeCheckEngine code, on request
Key release tied to a hardware measurement (confidential computing)
PlannedCheckToday release depends on software we operate; see What we do not claim
Identity and access
Each party signs in through an identity provider the plan trusts for its role (in the development setup: Keycloak for the authority, a Google sign-in we configured for the provider); a person acts only if the signed plan names them
In placeCheckdocs/threat-model.md
The authority's sign-in (Keycloak) requires a one-time code at every login, including the fresh login that signs a plan; repeated failures lock the account
In placeCheckKeycloak realm settings; engine runbook, on request
Sessions end after 30 minutes idle and 8 hours at most
In placeCheckEngine code, on request
Administrative consoles are not public; Cloudflare Access admits named administrators only
In placeCheckid.historlabs.eu/admin asks for Cloudflare Access
Qualified electronic signatures for plans
PlannedCheckNot built
Infrastructure
All public traffic is served over TLS through Cloudflare
In placeCheckAny *.historlabs.eu address
The ledger database accepts connections only from the control-plane server, over TLS verified against its CA
In placeCheckEngine runbook, on request
The console runs in a read-only container with no Linux capabilities
In placeCheckEngine runbook, on request
Every component is checked each minute from the server and from outside, with a public status page and email alerts
In placeCheckstatus.historlabs.eu
Point-in-time recovery for the ledger database
PartialCheckThe development database is on a free tier without it; the production design uses hourly backups
Supply chain
Releases of the verifier are signed with Sigstore keyless signing by the repository's own release workflow
In placeCheck
cosign verify-blobwith the identityhttps://github.com/historlabs/histor/.github/workflows/release.yml@refs/tags/v…, files from the latest releaseDependencies are locked with hashes; images and model artifacts are pinned by digest in the signed plan
In placeCheckpyproject.toml; the plan in the sample participation
Signed engine images with SBOMs and build provenance
PlannedCheckThe workflow exists; no engine release is published yet
Vulnerability management
A published disclosure policy with response targets
In placeCheckSECURITY.md
Independent penetration test
Not doneCheckNone so far
What we do not claim
Key release is software we operate
A key is released when software we run checks the signed plan and the harness's digest. An operator who can change that software could obtain a key. Hardware attestation is designed, not built.
No confidentiality undertaking from BSC
Root on a compute node could read model memory during a job, and no contract covers that yet.
Development hosting
The control plane is one server on a free tier and the ledger has no point-in-time recovery.
Sub-processors
Every third party that hosts, carries or processes data for the Histor service. Test data and model weights pass through no service that is not on this list.
| Entity | Purpose | Location | Data processed |
|---|---|---|---|
| Oracle Cloud | Hosts the control plane: console, authority sign-in, key store, run dispatcher | Amsterdam, NL | Plans, signatures, participants' staff data, keys and pull tokens, run results |
| Aiven (on DigitalOcean) | Managed PostgreSQL for the ledger | Amsterdam, NL | The hash-chained ledger, including participants' staff data |
| Cloudflare | DNS, TLS, tunnel to the control plane, access control, status page | Worldwide edge | All traffic to *.historlabs.eu; TLS ends at Cloudflare, so it can read traffic in transit |
| Barcelona Supercomputing Center (EuroHPC) | Runs the tests on MareNostrum 5 | Barcelona, ES | Model image, encrypted weights, test data; weights decrypted only in node memory |
| Runpod | Streams model images and encrypted weights from the registry to MareNostrum 5 | Romania, Czech Republic, Iceland | Image and encrypted weights in transit; nothing written to disk |
| GitHub | Container registry for model packages in the current pilot (a provider may use its own registry instead); source code | United States | Model image and encrypted weights; source |
| Google (Workspace and Cloud) | Email, including security reports and document requests; the provider's sign-in in the development setup | Worldwide | Email with participants' names and addresses; the provider's sign-in identity |
Documents
Public documents link to the open repository. The rest are sent on request by email.
- View
Verifier guide
How to check an evidence bundle and where to get trust anchors the operator could not have chosen
- View
Threat model
Each threat, its control, the evidence it leaves, and the risks stated rather than solved
- View
Evidence formats
Run attestation, inference profile, dataset commitment, check registry, JSON Schemas
- View
Sample participation
A complete synthetic evidence bundle with the verifier's verdict
- View
Signed release
The verifier as a wheel, with Sigstore bundles and checksums
- View
Vulnerability disclosure policy
How to report, and the response targets
- On request
Security pack
Architecture, who sees what, ISO/IEC 27001 Annex A mapping, residual risks, supply chain
- On request
Data protection position
What personal data the control plane and bundles hold, and what is needed before real data
- On request
Centre undertaking template
The confidentiality undertaking a computing centre signs before a run there; a starting point for counsel
FAQ
Can Histor see our test data or model?
The model's weights stay encrypted with the provider's key until they are in a compute node's memory. Test data is sealed and decrypted only inside the run; in the current pilot it is synthetic. We operate the software that releases keys, so we state this as a limit rather than a guarantee: see What we do not claim.
Do we have to trust Histor's report?
No. The evidence bundle can be checked with the public verifier, offline, against trust anchors you obtain yourself. If anything was altered, it fails.
Does Histor train models on our data?
No. Histor does not train models. It runs the tests both parties signed and records the result.
Is MareNostrum 5 contractually bound to confidentiality?
Not yet. BSC has signed no undertaking. Until one is signed, runs there use synthetic and public data only.
Do you have SOC 2 or ISO 27001?
No. Our controls are mapped to ISO/IEC 27001 Annex A, and the mapping is available on request. Nothing is certified.
Where is data stored?
The control plane and ledger are in Amsterdam, tests run in Barcelona. The sub-processor list gives every location.
How do I report a vulnerability?
Email security@historlabs.eu or use GitHub's private reporting on historlabs/histor. We acknowledge within 5 working days.
Updates
Trust centre published
This page, with the sub-processor list and our compliance position.
Public status page
Every component is checked each minute from the server and from outside, at status.historlabs.eu.
Verifier 0.1.0 released
The evidence formats and offline verifier, published under EUPL-1.2 and signed with Sigstore.
Found a security issue? Email security@historlabs.eu. We acknowledge within 5 working days.
Report on GitHub