A compliance change is a configuration change, not a release.
Most platforms answer a new regulation by editing a PDF. Whispor answers it by changing what the system is allowed to do. Guardrails, audit, retention and human oversight are enforced in the engine, so a compliance change takes effect in the product rather than in a policy binder.
Policy describes intent. Architecture enforces it.
The distinction matters most at the moment a rule changes, because that is when the two approaches visibly diverge.
A rule is written down.
The obligation lives in a document. Enforcement depends on whoever reads it, remembers it and applies it correctly under time pressure. When the rule changes, the document is revised and the product is unchanged until someone schedules the work.
Evidence is assembled after the fact, by asking people what happened and reconciling it against logs that were not designed to answer the question.
A rule is a constraint the engine holds.
The obligation is expressed as a guardrail, a retention rule, an approval gate or an oversight requirement that the negotiation engine reads before it acts. Nothing that violates it can be executed, because the path is not available.
Evidence is a by-product of running. Every action already carries the rule that permitted it, the data it saw and the human who approved it.
Express it once. The platform enforces it everywhere.
Whispor expresses key compliance requirements as guardrails, retention rules, approval gates and oversight controls within the platform. Many changes can therefore be applied through configuration rather than waiting for a product release.
Where Whispor stands.
What Whispor is aligned to, and where no certification exists for anyone to hold yet.
SOC 2
Aligned controls
Controls are mapped to the SOC 2 Trust Services Criteria: security, availability, processing integrity, confidentiality and privacy. Access control, change management, monitoring and incident response follow those criteria.
GDPR
Aligned controls
Lawful basis for processing, data-subject access, correction and erasure, purpose limitation, and data minimization are built into the data model. Processing records and retention schedules are maintained per tenant.
EU AI Act
Architected against
No certification body exists for the Act yet, so nobody can hold a conformity mark today. Whispor is built against its requirements: transparency about AI involvement, human oversight, logging and risk management.
State law is where the exposure actually sits.
Federal AI rules remain unsettled, so the binding obligations for a US buyer are at state level. These four drive the requirements a negotiation platform has to meet.
TRAIGA
Regulates intentional harmful use of AI, enforced by the Attorney General with a 60-day notice and cure period. Substantial compliance with the NIST AI Risk Management Framework is an affirmative defense. Whispor's guardrails, adversarial testing and preserved audit trails map to Govern, Map, Measure and Manage, which is what that defense asks you to evidence.
BIPA
Carries a private right of action and requires no proof of harm, which is why it produces the largest settlements in US privacy. Whispor collects and infers no biometric identifiers. No voiceprint, no faceprint, no emotion inference, so that category of exposure does not arise. Where call audio is processed, consent is attested and retention is bounded.
CUBI
Requires informed consent before a biometric identifier is captured for a commercial purpose, and sets destruction deadlines. Enforcement sits with the Attorney General. The same architectural answer applies. Whispor's signal model reads observable conduct and documentary evidence, not biometric identifiers.
CCPA / CPRA
Consumers hold rights to know, delete, correct and opt out of sale or sharing, with obligations flowing to service providers. Whispor processes customer data as a service provider under contract, does not sell or share personal information, and supports deletion and correction through the same tenant-scoped controls that serve GDPR.
What is actually implemented.
The controls a security questionnaire asks about, and where each one is enforced.
Tenant separation
Row-level security in the data layer, so a code defect cannot cross tenants.
In transit and at rest
TLS from browser to database. Encrypted at rest, including backups.
Least privilege by role
Access scoped to tenant and function. Admin paths are separate and logged.
Append-only action log
Entries cannot be edited afterwards. Each records the actor, the evidence and the outcome.
No cross-tenant training
The engine learns inside your boundary. Your data never trains another customer's model.
Attested before capture
No call is analyzed without attested consent. The assistant announces itself when it joins.
Bounded and configurable
Retention windows are set per tenant. Deletion propagates through derived records.
Human approval gates
Assist recommends, a person decides. Autonomous escalates rather than exceeding its mandate.
Tested backups
Encrypted, scheduled and stored separately. Restores are tested rather than assumed.
We report what was said and done.
Whispor observes conduct and cites the evidence for every signal it raises. It does not claim to read minds, detect emotions, or judge truthfulness, and it does not profile people. Your counterparties are treated as fairly as your own team. This is a design constraint rather than a preference, and it is the reason whole categories of biometric and inference risk do not apply to the platform.
Have a supplier negotiation coming up?
Bring us the situation. We will show you how Whispor would prepare for it, what Whispor Assist would surface, and where autonomous negotiation could extend your team's coverage.