Compliance Framework
AmericanAGI maintains a comprehensive compliance program designed for deployment across DoD, intelligence community, and civilian federal agencies. Our systems are built to meet or exceed the following standards:
| STANDARD | SCOPE | STATUS |
|---|---|---|
| FedRAMP High | Cloud security for high-impact federal systems | IN PROGRESS |
| NIST SP 800-53 Rev. 5 | Security and privacy controls — High baseline | ALIGNED |
| NIST AI RMF 1.0 | AI risk management framework | ALIGNED |
| FIPS 140-3 | Cryptographic module validation | COMPLIANT |
| ITAR (22 CFR 120-130) | Export control for defense articles and services | COMPLIANT |
| EAR (15 CFR 730-774) | Export control for dual-use technology | COMPLIANT |
| CMMC Level 3 | Cybersecurity maturity for defense contractors | TARGET |
| SOC 2 Type II | Service organization security controls | IN PROGRESS |
| DoD IL-6+ | Impact level for classified data processing | TARGET |
Export Control
AmericanAGI systems and technical data are subject to ITAR and EAR export controls. Key provisions:
- No foreign person access to controlled technical data without authorization
- All training data, model weights, and architecture specifications are ITAR-controlled
- Technology Control Plans (TCPs) govern physical and digital access to controlled items
- Deemed export controls apply to all on-site personnel
AI Governance
Our AI governance framework aligns with the NIST AI Risk Management Framework and includes:
- Bias testing: Regular evaluation across protected categories with documented remediation
- Interpretability: Auditable reasoning traces for all high-stakes inference outputs
- Human oversight: Multi-party authorization gates for consequential decisions
- Incident response: Documented procedures for AI safety incidents with mandatory reporting
Data Governance
- All data classified per NIST SP 800-60 and processed accordingly
- Data residency restricted to CONUS facilities at all times
- Role-based access control with least-privilege enforcement
- Continuous monitoring per NIST SP 800-137
Contact
For compliance inquiries or to request documentation, contact compliance@americanagi.cc.