Compliance posture is determined principally by customer-hosted deployment and the metadata-only boundary. Together they narrow the regulatory scope of the platform itself, while preserving your ability to satisfy requirements across your broader environment.
Pathix deploys into your Azure subscription from a Bicep template. There is no vendor production infrastructure that processes customer data, so there is no vendor control environment for an auditor to assess in the first place.
Pathix has no generic Retrieve method and no value, content, or data column. Record bodies have no path into the system, which keeps Pathix outside the scope of the frameworks that attach to record content.
This describes how Pathix's architecture interacts with each framework. It is not a certification, an attestation, or an audit opinion, and it does not certify your environment. Where a row says your subscription provides the control environment, the assessment of that environment remains yours.
Deployment model, identity, cryptography, telemetry, and the shared-responsibility matrix.
Read →23 security findings mapped to SOC 2, ISO 27001:2022, and NIST 800-53, plus 17 operational findings.
Read →Where the Pathix database lives, what is in it, and what is deliberately not.
Read →We will answer it against the actual code paths and the Bicep template, not a marketing summary.