Security & compliance
Audit-ready, because you can read the code
The privacy boundary is open source. Your reviewers can confirm exactly what is captured and what is dropped, line by line, before anything is deployed. No certificate to take on faith.
Two-layer boundary
The SDK redacts in the page, but the backend never trusts the client. Every trace is scrubbed again on the server before it is stored. Defense in depth, proven by a named test.
Never captured
Mapped to the regulations your reviewers cite
SEC Reg S-P (2024)
Safeguards and recordkeeping. Incident records retained five years.
Internal model-risk principles
Named, runnable gates for auditability, monitoring, and human oversight. The 2026 interagency MRM guidance excludes generative and agentic AI from its scope, so StepStitch does not claim it applies.
NIST AI RMF
Data governance, documentation, accountability, incident response.