What Inviolet records for every decision
Each decision produces one immutableintent_events record carrying:
Beyond the individual record, Inviolet continuously measures whether its autonomous decisions stay correct over time — accuracy against human corrections, override rate, and shadow-vs-enforced divergence — the post-market monitoring regulators increasingly expect.
EU AI Act
GDPR Article 22 — automated decisions
SEC — recordkeeping for regulated firms
California — CCPA ADMT regulations
California’s other 2026 AI laws (SB 53 frontier-model transparency, SB 942 content
watermarking, SB 243 companion chatbots, AB 325 algorithmic pricing) generally apply to
different actors — frontier developers, consumer content generators, chatbot operators.
Where a customer is subject to them, Inviolet’s decision and incident logs supply
supporting evidence, but they do not impose direct obligations on the gateway itself.
Retention
Log-retention floors under the EU AI Act (6 months) and SEC rules (multi-year) are met on the Ultraviolet tier, which retains decision records indefinitely. Lower tiers retain records for shorter windows; organizations subject to EU or SEC retention duties should deploy on Ultraviolet.Continuous streaming to your GRC platform
Because every decision emits an event the moment it happens, Inviolet streams evidence continuously into your governance-risk-compliance platform (Hyperproof, and other GRC systems) — each artifact mapped to the specific control it satisfies. Evidence collection is real time, not a quarterly scramble.Read next
- Six enforcement layers — where in the pipeline decisions are made.
- Decision feed — the in-product view of the evidence described here.
- Tier comparison — retention and compliance capabilities by tier.