Skip to main content
Governance and assurance

Governance and assurance

One page, plainly stated: what runs in production today, what is designed and not yet built, and what an institutional buyer needs in order to run their own assessment.

Northflow holds no formal certifications. Where we reference a framework, we are describing design intent and a target operating model, not accreditation, audit completion, or regulatory approval.

Operational today

Evidence verification, running and red-team tested.

OperationalThe one assurance capability that is live and independently checkable.

Every HGE execution produces a signed evidence bundle: a 5-step verification contract with SHA-256 integrity hashes, Ed25519 digital signatures, deterministic replay, and audit invariants. The generation, storage, and verification pathways were red-team tested against six adversarial attack vectors. Governance modes (disabled, logging, enforced) allow graduated institutional deployment.

SHA-256 evidence hashes and Ed25519 signatures
Deterministic replay for independent verification
Audit invariants and policy gating
Red-team tested: 6 adversarial attack vectors

The distinction that matters

Alignment versus certification.

Framework alignment describes the design approach and operational methodology we employ. It does not constitute formal certification, accreditation, or regulatory approval.

Alignment indicates that:

  • Systems are designed with framework requirements as foundational principles
  • Operational procedures incorporate framework methodologies
  • Documentation and governance structures reflect framework standards
  • We monitor regulatory developments continuously

Alignment does not indicate:

  • Formal certification by accredited bodies
  • Regulatory approval or endorsement
  • Legal compliance guarantees for specific use cases
  • Audit completion or attestation

Institutional stakeholders should conduct independent compliance assessment appropriate to their specific regulatory context and operational requirements.

Designed, not built

What is designed and not yet built.

The following are reference architectures and defined frameworks, not fielded services. They carry no status badge on purpose: a badge would invite a reader to mistake intent for implementation. Read this as a roadmap.

Access control and identity management

Role-based access control, privileged access management, multi-factor authentication for privileged operations, and segregation of duties. Designed, not fielded as a hardened service.

Cryptographic protection at rest and in transit

Encryption of data at rest and in transit with institutional key-management procedures. Design aligned with European standards; not independently assessed.

Incident response

Detection, containment, investigation, and notification protocols aligned with European regulatory requirements. A defined framework, not a staffed operating capability.

Sovereign data infrastructure

Reference architecture for data residency, jurisdictional controls, and lineage tracking. Design work; no implementation to point at.

Operational continuity

Continuity planning, failover, and recovery procedures oriented to ISO 22301 principles. Design work; no fielded continuity service.

Framework alignment

The frameworks that apply to this business.

We reference only the frameworks relevant to European institutional evidence infrastructure. Framework relevance varies by jurisdiction, sector, and mandate. Nothing here is a certification claim.

GDPR

General Data Protection Regulation

Data protection principles, processing requirements, and individual rights embedded in system architecture.

NIS2 Directive

Network and information security

Security requirements, incident reporting, and risk-management measures aligned with the European cybersecurity directive.

ISO/IEC 27001

Information security management

Security controls, risk-management methodology, and information-security governance aligned with the international standard.

DORA

Digital Operational Resilience Act

Operational resilience requirements, testing frameworks, and third-party risk management aligned with financial-sector regulation.

ISO 22301

Business continuity management

Continuity planning, resilience frameworks, and recovery procedures aligned with the business-continuity standard.

For institutional buyers

What you need to run your own assessment.

We do not ask you to take assurance on trust. The operational parts of the platform are built to be checked directly.

Open the evidence

Signed evidence bundles with deterministic replay let you reproduce any finding and verify its integrity independently.

Open the ledger

The CERES ledger records every forecast before its outcome is known, and grades it against IPC at T+90 once that outcome publishes. None are graded yet, because IPC publishes two to four months behind; the ledger carries the live count. A write-once record cannot be quietly edited, and 172 forecasts withdrawn from the score in March remain readable with the reason attached.

Open the source

PSE (Apache 2.0) and ClimVal (PyPI, Apache 2.0) are public. You can read the pipelines that produce the data.

Request the documentation

Framework mapping, control implementation detail, and red-team results are available to institutional stakeholders on request.

Institutional due diligence.

For framework mapping, control documentation, or a governance assessment, talk to us. For everything already public, use the systems directly.