LexAudit compliance monitor is part of BizLegal. 24/7 ops, $2,500/mo.See the offer →
Skip to main content

Disclosure v1.0.0-p1

LexAudit methodology.

How LexAudit produces compliance health-score intelligence and attestation artefacts. Framework coverage, signal registries, scoring weights, human review, and what the attestation is and is not.

Framework coverage.

LexAudit evaluates a customer's posture against five frameworks. The signal registry below is the vv1.0.0-p1 published set — 60 signals total, 12 per framework, each mapped to a real published control in its source framework.

SOC 2 (AICPA TSC)12 signals
  • CC1.1 · Integrity and ethical values
  • CC2.1 · Information and communication
  • CC3.1 · Risk identification
  • CC5.1 · Control activities selection
  • …and 8 more in the full registry
ISO/IEC 27001:202212 signals
  • A.5.1 · Policies for information security
  • A.5.7 · Threat intelligence
  • A.5.15 · Access control policy
  • A.5.19 · Supplier security
  • …and 8 more in the full registry
GDPR (EU 2016/679)12 signals
  • Art. 5 · Principles of processing
  • Art. 6 · Lawful basis for processing
  • Art. 7 · Conditions for consent
  • Art. 13 · Information to data subjects
  • …and 8 more in the full registry
HIPAA Security Rule (45 CFR §164)12 signals
  • §164.308(a)(1) · Security management process
  • §164.308(a)(3) · Workforce security
  • §164.308(a)(4) · Information access management
  • §164.308(a)(5) · Security awareness and training
  • …and 8 more in the full registry
DPDP Act 2023 (India)12 signals
  • Sec. 5 · Notice to data principals
  • Sec. 6 · Consent
  • Sec. 7 · Certain legitimate uses
  • Sec. 8 · Obligations of data fiduciary
  • …and 8 more in the full registry

Signals and scoring.

Each signal carries a weight, a rationale, and an evidence-collection rule describing what artefact substantiates the signal. Scores are deterministic given the evidence; if evidence is missing, the signal is marked "insufficient evidence" rather than defaulted.

Human review.

Every score and every attestation artefact is reviewed by a named analyst before release. The analyst verifies that the evidence cited for each signal actually supports the assigned value, flags uncertainty the engine did not, and can hold delivery if any signal cannot be substantiated.

What the attestation artefact is, and is not.

The LexAudit attestation artefact is a process record: it attests that a customer's documented AI-assisted workflow followed its published process, with the evidence timestamps and reviewer signoff preserved. It does not certify the customer as compliant with any framework; a framework compliance finding is made by an independent auditor or a regulator, neither of which LexAudit is. The seven-clause disclosure on every page governs.

Handling uncertainty.

When evidence is missing, when a framework signal maps ambiguously, or when a review reveals inconsistency, we say so. "Insufficient evidence," "conflicting sources," and "out of scope" are acceptable outputs. We prefer a conservative admission to a confident fabrication.

Versioning.

Every health-score report and every attestation artefact carries a disclosure version stamp (v1.0.0-p1 at the time this page was generated) and an issued_at timestamp. If an assertion is ever challenged, the stamp lets us reproduce exactly which disclosure was in force and which signal weights were active at issue time.

Incident response.

If an attestation or a health-score is challenged — by a customer, an auditor, or a regulator — we follow the Liability Incident Response SOP published on the hub workflows library. Preservation first, notification to counsel next, no fault admission prior to review.

Disclosure v1.0.0-p1

What we are. What we are not.

We are not a law firm.

BizLegal AI is a regulatory intelligence platform. We do not practice law in any jurisdiction. Accessing this site or using our tools does not create an attorney-client relationship.

Every output passes human review.

No intelligence ships to a customer without a named human reviewer signing off. The reviewer verifies sources, flags uncertainty, and can hold delivery if any assertion cannot be substantiated.

We do not file on your behalf.

We do not submit filings to FinCEN, the SEC, a court, a registry, or any other regulator for you. Where our output references a filing, you remain the filer of record and are responsible for submission, timing, accuracy, and consequences.

Jurisdictional scope is finite.

Our intelligence covers specified jurisdictions and frameworks. Gaps exist. If a question sits outside our coverage, we say so rather than infer. The pages listing covered jurisdictions and frameworks control.

Regulation changes. We do not warrant currency.

Regulatory texts, enforcement postures, and guidance evolve continuously. We make reasonable efforts to keep intelligence current, but we do not warrant that any output is complete or up-to-date at the moment you act on it. The disclosure version and issue timestamp on each output pin what was in force when the intelligence was produced.

Limits of liability.

Use of our intelligence is at your own risk and, where applicable, subject to the liability limits in our Terms. We are not liable for outcomes of decisions you make after reading our intelligence, including filings you submit, contracts you sign, or transactions you execute. If you have a complaint or a concern about a specific output, our incident response procedure is published on the Trust page.

BizLegal AI publishes regulatory intelligence. We are not a law firm. This is not legal advice. All output is reviewed by a human analyst before release and is subject to the version-stamped disclosure in force at the moment of issue.

BizLegal AI publishes regulatory intelligence. We are not a law firm. This is not legal advice. All output is reviewed by a human analyst before release and is subject to the version-stamped disclosure in force at the moment of issue.

Disclosure v1.0.0-p1 · Links: Disclaimer · Trust · Methodology