Auditable by design

Trust & compliance

Assessment vendors usually treat compliance as paperwork bolted on at procurement. Equilibrium was built the other way round: the consent record, the audit log and the bias audit are product surfaces your team uses, not documents we email you.

Compliance centre

What ships in the product

Consent ledger

Every consent is purpose-specific, versioned to the exact text shown, and timestamped. Revocation is a first-class action: it stops future processing and flags the aggregates the person contributed to.

  • GDPR Art 7
  • EU AI Act Art 26
  • State biometric & AI notice laws

Exportable audit trail

Append-only logging of every score-affecting event and every report view: who, when, which norm version, which item parameters, which export. Customers export the whole trail as CSV or JSON — it is your record, not ours.

  • NYC LL144 record-keeping
  • EU AI Act Art 12 logging
  • SOC-style evidence requests

Bias-audit workbench

Optional, separately consented self-ID stored in a segregated table with tightened access. Per-construct distributions and impact ratios across groups and intersections, using both the four-fifths rule and a 2-SD test, exported as a dated audit artefact.

  • NYC LL144 bias audit
  • Uniform Guidelines 4/5ths
  • Illinois & Colorado AI provisions

Human-in-the-loop gates

Any org-side view that could inform a decision requires a named reviewer and a written rationale before it can be exported. Reviewers whose median review time falls under ten seconds are flagged as rubber-stamping.

  • GDPR Art 22
  • EU AI Act Art 14 human oversight

Notice manager

Per-region compliance modes (NYC, IL, TX, CA, CO, EU) switch on the matching templates: pre-use disclosure, adverse-outcome notice workflow, and a dispute and data-correction queue with a 30-day SLA tracker.

  • LL144 candidate notice
  • State pre-use disclosure
  • EU AI Act transparency

Data rights & retention

Subject-access export in a machine-readable, portability-shaped format, and deletion by crypto-shredding — we destroy the key rather than rewrite an append-only log, so the audit record stays intact while the person's data becomes unreadable. Retention purge jobs are configurable per region.

  • GDPR Art 15, 17, 20
  • Australian Privacy Principles 11 & 12

Data handling

Our standing posture

  • Assessment data is stored in-region and encrypted in transit and at rest.
  • Managers never see an individual's item responses — only aggregates at n ≥ 5.
  • Language models never generate, alter or estimate a score; generated narrative is machine-checked against the engine's own numbers before display.
  • No item touches health, religion, sexuality, or DSM-correlated content.
  • Every output is advisory. The product will not render any score as a solely-automated decision about a person.
Configurable compliance tooling — not legal advice. The features above help you evidence your obligations; they do not determine them. Validate your deployment with counsel in each jurisdiction you operate in.