Evidence and disclosure

What we claim, and what we do not

This page states the public boundary around Three Gates' architecture, security posture, compliance work, and company stage. It is written to answer diligence questions without implying evidence we do not have.

Current as of September 11, 2026.

Our standard

Specific claims. Visible boundaries.

A design goal is not a certification. A planned audit is not an audit in progress. A guarantee about detected data is not a guarantee of perfect detection. We keep those distinctions explicit.

Sensitive-data handling

What we claim

Detected sensitive values are tokenized before every model invocation, in every tier.

Boundary

Detection is probabilistic. We do not claim that every sensitive identifier will be detected.

HIPAA and BAAs

What we claim

Three Gates is designed to support HIPAA Security Rule obligations and is BAA-ready for healthcare customers.

Boundary

We do not claim HIPAA certification or describe the platform as universally HIPAA compliant.

NIST frameworks

What we claim

Three Gates is architected to the NIST SP 800-53 Rev. 5 Moderate baseline and aligned with NIST AI RMF 1.0.

Boundary

We do not claim NIST certification, accreditation, or third-party attestation.

SOC 2 and HITRUST

What we claim

A SOC 2 Type II audit is planned and customer-engagement-gated. HITRUST i1 is planned to follow the initial SOC 2 Type II report.

Boundary

Neither certification is held, and no audit or assessment is currently described as in progress.

Security testing

What we claim

Internal security review and dependency vulnerability scanning are operational.

Boundary

Third-party penetration testing is planned and customer-engagement-gated. We do not claim that it has occurred.

Encryption keys

What we claim

Customer-managed encryption keys for stored work product are supported, including keys in a customer-controlled Azure Key Vault.

Boundary

This does not imply private connectivity, dedicated infrastructure, or customer control of every platform key.

Policy controls

What we claim

PHI policy is enforced before model invocation. Requests are authorized against a declared purpose and routed by risk level.

Boundary

We do not market retired policy modes, a policy playground, destination overrides, or natural-language policy management as current product surfaces.

Company stage

What we claim

Three Gates is pre-GA and accepting applications for a small design partner program.

Boundary

We do not claim paying customers, production healthcare deployments, or customer logos.

Read the supporting evidence

Review measured detection results and the documented FHIR prototype.