mona-agent / docs /COMPLIANCE.md
mo
docs: compliance & trust β€” CRA, NIS2, EU AI Act, GDPR, SBOM
2eea493
|
Raw History Blame Contribute Delete
5.09 kB

Compliance & Trust

mona-agent and the mona.expert cloud are designed with the modern EU regulatory landscape in mind. This document summarises our position for each framework: what applies, what is in place today, and how it maps to the product.

Transparency note: the statements below describe readiness and alignment, not third-party certifications. Where a formal audit, certification or conformity assessment applies to your use case, it is performed in the context of the mona.expert cloud service.

Frameworks at a glance

Framework Scope Applies to Position
EU Cyber Resilience Act (CRA) Products with digital elements mona.expert cloud (SaaS) Readiness program in place β€” SBOM, vulnerability handling, coordinated disclosure, secure-by-design development
NIS2 Directive Network & information systems security Essential / important entities Supports customer obligations β€” logging, TOMs, incident assistance
EU AI Act AI systems mona-agent + engine (limited risk) Transparency obligations implemented; documentation below
GDPR Personal data mona.expert cloud Privacy by design, data minimisation, DPA-ready documentation

Cyber Resilience Act (CRA)

The CRA requires products with digital elements to be secure by design, shipped with vulnerability handling processes, security updates, and documentation β€” and to report exploited vulnerabilities to ENISA.

  • Open-source client (mona-agent) β€” free, MIT-licensed, supplied outside commercial activity: outside the CRA's main obligations. We still apply the same discipline: secure defaults, dependency minimisation, coordinated disclosure.
  • mona.expert cloud (the SaaS) β€” treated as in scope. Readiness elements in place:
    • SBOM β€” see SBOM.md (sbom.cyclonedx.json); one runtime dependency (ws), updated continuously.
    • Vulnerability handling β€” SECURITY.md: 48 h acknowledgment, 14-day fix + coordinated disclosure, ENISA-style reporting path (security@mona.expert).
    • Secure by design / by default β€” AES-256-GCM encryption at rest for all stored keys, TLS in transit, least-privilege tool sandbox, no inbound ports on devices.
    • Security updates β€” the client updates in place with a single command; the cloud ships continuously.
    • Documentation & conformity β€” this document set + risk controls below.

NIS2

NIS2 applies to essential and important entities (energy, transport, health, digital infrastructure, etc.). mona.expert is not classified as such today β€” but we build so that NIS2 customers can meet their own duties when using us:

  • Risk management β€” documented TOMs (technical and organisational measures): encryption, access control, monitoring, backup.
  • Supply chain security β€” minimal dependencies, pinned versions, dependency review on change.
  • Incident handling β€” severity-based response, 48 h triage, customer notification, audit trail of every action (mona_audit_log).
  • Logging & detection β€” per-user audit log, rate limiting, anomaly-friendly telemetry.

EU AI Act

See the dedicated AI Act documentation. Summary: mona-agent is a limited-risk AI system (agent assistant / device automation). Transparency obligations (disclosure of AI interaction, documentation, logging, human oversight) are implemented. We are not a general-purpose model provider; the mona.expert engine orchestrates third-party models on behalf of the user.

GDPR

See the dedicated GDPR documentation. Summary: data minimisation by design (metrics only, no key material on devices), AES-256 vault, documented processing purposes, retention limits, and a prepared data-processing annex for customers.

Security measures (TOMs)

Domain Measure
Encryption at rest AES-256-GCM vault for all API keys and tokens
Encryption in transit HTTPS/TLS for every connection; no plaintext endpoints
Access control Per-user bearer tokens, session auth, CSRF protection, per-user rate limits
Least privilege Device tool sandbox β€” allowlisted shell, confined file roots, egress-only networking
Logging & audit Immutable-style audit log of agent actions, LLM calls, key events
Resilience Stateless API, automatic reconnect, HTTP fallback channel, 180-point device history
Incident response SECURITY.md β€” 48 h acknowledgment, coordinated disclosure, advisory publishing

Certifications roadmap

Formal attestations are tracked for the mona.expert cloud. Planned: SOC 2 Type I (process documentation first), ISO/IEC 27001 alignment (reuse of the controls above), and CRA conformity assessment once the delegated acts finalise. The open-source client itself remains certification-free by design (MIT, minimal surface).

Questions

Compliance questions: compliance@mona.expert. Security issues: security@mona.expert (see SECURITY.md).