Compliance & Security

A compliance change is a configuration change, not a release.

Most platforms answer a new regulation by editing a PDF. Whispor answers it by changing what the system is allowed to do. Guardrails, audit, retention and human oversight are enforced in the engine, so a compliance change takes effect in the product rather than in a policy binder.

The difference

Policy describes intent. Architecture enforces it.

The distinction matters most at the moment a rule changes, because that is when the two approaches visibly diverge.

Policy compliance

A rule is written down.

The obligation lives in a document. Enforcement depends on whoever reads it, remembers it and applies it correctly under time pressure. When the rule changes, the document is revised and the product is unchanged until someone schedules the work.

Evidence is assembled after the fact, by asking people what happened and reconciling it against logs that were not designed to answer the question.

Architectural compliance

A rule is a constraint the engine holds.

The obligation is expressed as a guardrail, a retention rule, an approval gate or an oversight requirement that the negotiation engine reads before it acts. Nothing that violates it can be executed, because the path is not available.

Evidence is a by-product of running. Every action already carries the rule that permitted it, the data it saw and the human who approved it.

When the rules change

Express it once. The platform enforces it everywhere.

Whispor expresses key compliance requirements as guardrails, retention rules, approval gates and oversight controls within the platform. Many changes can therefore be applied through configuration rather than waiting for a product release.

01 · ExpressThe obligation is written once, as a constraint the platform can read.
02 · BindIt attaches to the tenant, jurisdiction, category or the single negotiation.
03 · EnforceThe engine reads constraints before acting. It cannot act outside them.
04 · EvidenceEvery action records which rule allowed it.
Frameworks

Where Whispor stands.

What Whispor is aligned to, and where no certification exists for anyone to hold yet.

SOC 2

Aligned controls

Controls are mapped to the SOC 2 Trust Services Criteria: security, availability, processing integrity, confidentiality and privacy. Access control, change management, monitoring and incident response follow those criteria.

GDPR

Aligned controls

Lawful basis for processing, data-subject access, correction and erasure, purpose limitation, and data minimization are built into the data model. Processing records and retention schedules are maintained per tenant.

EU AI Act

Architected against

No certification body exists for the Act yet, so nobody can hold a conformity mark today. Whispor is built against its requirements: transparency about AI involvement, human oversight, logging and risk management.

On the timeline. Article 50 transparency obligations applied from 2 August 2026. The high-risk regime under Annex III was deferred to 2 December 2027, and product-embedded systems under Annex I to 2 August 2028. Penalties reach €35M or 7% of global turnover. Whispor's oversight, logging and risk controls are in place now rather than scheduled against those dates.
United States

State law is where the exposure actually sits.

Federal AI rules remain unsettled, so the binding obligations for a US buyer are at state level. These four drive the requirements a negotiation platform has to meet.

Texas · effective 1 Jan 2026

TRAIGA

Regulates intentional harmful use of AI, enforced by the Attorney General with a 60-day notice and cure period. Substantial compliance with the NIST AI Risk Management Framework is an affirmative defense. Whispor's guardrails, adversarial testing and preserved audit trails map to Govern, Map, Measure and Manage, which is what that defense asks you to evidence.

Illinois

BIPA

Carries a private right of action and requires no proof of harm, which is why it produces the largest settlements in US privacy. Whispor collects and infers no biometric identifiers. No voiceprint, no faceprint, no emotion inference, so that category of exposure does not arise. Where call audio is processed, consent is attested and retention is bounded.

Texas

CUBI

Requires informed consent before a biometric identifier is captured for a commercial purpose, and sets destruction deadlines. Enforcement sits with the Attorney General. The same architectural answer applies. Whispor's signal model reads observable conduct and documentary evidence, not biometric identifiers.

California

CCPA / CPRA

Consumers hold rights to know, delete, correct and opt out of sale or sharing, with obligations flowing to service providers. Whispor processes customer data as a service provider under contract, does not sell or share personal information, and supports deletion and correction through the same tenant-scoped controls that serve GDPR.

Controls in place

What is actually implemented.

The controls a security questionnaire asks about, and where each one is enforced.

Tenant separation

Row-level security in the data layer, so a code defect cannot cross tenants.

In transit and at rest

TLS from browser to database. Encrypted at rest, including backups.

Least privilege by role

Access scoped to tenant and function. Admin paths are separate and logged.

Append-only action log

Entries cannot be edited afterwards. Each records the actor, the evidence and the outcome.

No cross-tenant training

The engine learns inside your boundary. Your data never trains another customer's model.

Attested before capture

No call is analyzed without attested consent. The assistant announces itself when it joins.

Bounded and configurable

Retention windows are set per tenant. Deletion propagates through derived records.

Human approval gates

Assist recommends, a person decides. Autonomous escalates rather than exceeding its mandate.

Tested backups

Encrypted, scheduled and stored separately. Restores are tested rather than assumed.

Signal doctrine

We report what was said and done.

Whispor observes conduct and cites the evidence for every signal it raises. It does not claim to read minds, detect emotions, or judge truthfulness, and it does not profile people. Your counterparties are treated as fairly as your own team. This is a design constraint rather than a preference, and it is the reason whole categories of biometric and inference risk do not apply to the platform.

Real negotiation. Real context.

Have a supplier negotiation coming up?

Bring us the situation. We will show you how Whispor would prepare for it, what Whispor Assist would surface, and where autonomous negotiation could extend your team's coverage.