Disclosure v1.0.0-p1
LexAudit methodology.
How LexAudit produces compliance health-score intelligence and attestation artefacts. Framework coverage, signal registries, scoring weights, human review, and what the attestation is and is not.
Framework coverage.
LexAudit evaluates a customer's posture against five frameworks. The signal registry below is the vv1.0.0-p1 published set — 60 signals total, 12 per framework, each mapped to a real published control in its source framework.
CC1.1· Integrity and ethical valuesCC2.1· Information and communicationCC3.1· Risk identificationCC5.1· Control activities selection- …and 8 more in the full registry
A.5.1· Policies for information securityA.5.7· Threat intelligenceA.5.15· Access control policyA.5.19· Supplier security- …and 8 more in the full registry
Art. 5· Principles of processingArt. 6· Lawful basis for processingArt. 7· Conditions for consentArt. 13· Information to data subjects- …and 8 more in the full registry
§164.308(a)(1)· Security management process§164.308(a)(3)· Workforce security§164.308(a)(4)· Information access management§164.308(a)(5)· Security awareness and training- …and 8 more in the full registry
Sec. 5· Notice to data principalsSec. 6· ConsentSec. 7· Certain legitimate usesSec. 8· Obligations of data fiduciary- …and 8 more in the full registry
Signals and scoring.
Each signal carries a weight, a rationale, and an evidence-collection rule describing what artefact substantiates the signal. Scores are deterministic given the evidence; if evidence is missing, the signal is marked "insufficient evidence" rather than defaulted.
Human review.
Every score and every attestation artefact is reviewed by a named analyst before release. The analyst verifies that the evidence cited for each signal actually supports the assigned value, flags uncertainty the engine did not, and can hold delivery if any signal cannot be substantiated.
What the attestation artefact is, and is not.
The LexAudit attestation artefact is a process record: it attests that a customer's documented AI-assisted workflow followed its published process, with the evidence timestamps and reviewer signoff preserved. It does not certify the customer as compliant with any framework; a framework compliance finding is made by an independent auditor or a regulator, neither of which LexAudit is. The seven-clause disclosure on every page governs.
Handling uncertainty.
When evidence is missing, when a framework signal maps ambiguously, or when a review reveals inconsistency, we say so. "Insufficient evidence," "conflicting sources," and "out of scope" are acceptable outputs. We prefer a conservative admission to a confident fabrication.
Versioning.
Every health-score report and every attestation artefact carries a disclosure version stamp (v1.0.0-p1 at the time this page was generated) and an issued_at timestamp. If an assertion is ever challenged, the stamp lets us reproduce exactly which disclosure was in force and which signal weights were active at issue time.
Incident response.
If an attestation or a health-score is challenged — by a customer, an auditor, or a regulator — we follow the Liability Incident Response SOP published on the hub workflows library. Preservation first, notification to counsel next, no fault admission prior to review.