Is sipi.bot SOC 2 Compliant?
The honest answer: we don't make certification claims in this page. Here's exactly what sipi.bot provides, and how to verify current compliance posture.
What sipi.bot provides
Deterministic spend controls — rules that can't be argued with or injected.
A queryable audit log of every decision, with the rule that fired.
Merchant allowlists and approval workflows for vendor governance.
What we don't claim here
Certification status (SOC 2, ISO 27001) is a moving target — verify the current posture with the team before relying on it in procurement.
How to evaluate
Ask for the current compliance documentation, run the eval gym yourself (the core is MIT), and test the audit log against your requirements.
At a glance
| Question | Answer |
|---|---|
| Deterministic controls | Yes — rules engine, no model in the path |
| Audit log | Yes — every decision logged |
| Certification status | Verify current posture with the team |
| Self-host option | Yes — MIT core |
FAQ
Can I self-host for compliance?
Yes — the MIT core runs in your environment, which can simplify compliance in some regimes.
Where do I verify compliance?
Contact the team for current documentation; don't rely on marketing pages.
Related
Stop the next $12,400 night.
One API call (or MCP tool) in front of every agent transaction — APPROVED, BLOCKED, or FLAGGED, deterministic, ~5 ms, fully logged.
See plans — from $99/mo Try a live check