Governance you can
hand to an auditor.
Compliance dossiers for ISO/SAE 21434, UN R155, GB 44495-2024† and EU CRA are assembled from the item definitions, TARA and risk-treatment evidence already in the project — every approval and mutation sealed into a tamper-evident audit chain. Nothing is retyped, and nothing is taken on the reviewer's word.
Policy, catalogs
& org rules.
Organization regulations and project policy — including the ISO 26262↔CSMS safety-security coupling gate — decide which controls and review gates apply before a risk decision counts as closed. Controls, threats and requirements live in governed catalogs (referenced, not copied), and automations enforce the gates and assemble evidence without manual steps.
Four-eyes,
or it doesn't count.
Sensitive changes — an authored work-product, an official-template publish, a CAL determination — require a second reviewer. The server rejects self-approval outright; the sealed approval, not a status field, is what downstream evidence is verified against.
BREAK ANY LINK → EVERY DOWNSTREAM CLAIM RE-FLAGS. AUTOMATICALLY.
A tamper-evident
audit chain.
Every mutation — generate, share, approve, revoke, rotate — is sealed into an insert-only, HMAC-chained, per-tenant-year audit log. Nothing can be edited after the fact; a GDPR erasure pseudonymizes the actor without breaking the chain.
Dossiers assembled,
not authored.
Readiness-gated generation pulls item definition, TARA, risk treatment, V&V and SBOM evidence straight into ISO/SAE 21434, UN R155, GB 44495-2024† and EU CRA dossiers — OEM type-approval and Tier-1 scoped-evidence variants held apart by a hard query-layer boundary, never blended.
