ArcaKey Continuous Defensibility Monitoring Report
This is a redacted reference excerpt of the report a Monitoring Pro customer receives weekly. Customer details are fictional. Report structure and signal table mirror the production template.
Report header
- Customer
- Acme Regulatory Strategy LLC (fictional reference)
- Subscription
- Monitoring Pro
- Reporting period
- 2026-04-01 through 2026-04-30
- Frameworks monitored
- Title 21 · NIST AI RMF · PHIPA (Ontario)
- Issued
- 2026-05-01
- Independent Verifier
- [Name, Title, Affiliation]
Executive summary
During the April 2026 reporting period, Acme's defensibility posture against the monitored frameworks held without material degradation. Three signals reached an Observational severity threshold; one signal reached Moderate. Details below. No Critical or High severity signals triggered.
Posture verdict: Stable. Recommend no immediate remediation. One Moderate finding warrants a 30-day follow-up.
Signals reaching threshold during this period
Tinfoil published an update to its supported model list on 2026-04-12. Acme's current ArcaVoice tier maps to Llama 3.3 70B; the update did not affect that model. No action required.
ArcaKey's Slice 13 correction-memory feature shipped as encrypted at rest (PR #243, 2026-05-15 — just before period close). Acme's correction memory data was migrated successfully; verified by HMAC integrity check. No action required; informational.
Drug Formulary delta: 4 new generic-form drugs added to the Health Canada DPD during the reporting period. None affect drugs commonly appearing in Acme's transcribed encounters during the previous 6 months. No action required.
Sub-processor BAA: ArcaKey's OpenAI BAA was renewed during the period under ArcaKey AI, LLC entity. Acme's documented sub-processor chain reflects the prior BAA which referenced an outdated ArcaKey legal entity name. Recommend Acme update internal sub-processor documentation to reflect the renewed BAA. Effort estimate: 30 minutes. Documentation template included as Appendix A of this report.
AI-stack posture summary
| Signal | This period | Previous | Status |
|---|---|---|---|
| TEE attestation digest stability | 100% (no drift) | 100% | OK |
| Audit-chain gap rate | 0 gaps in 14,832 entries | 0 gaps in 12,109 entries | OK |
| Per-encounter signature spot-check pass rate | 100% (148 / 148) | 100% (121 / 121) | OK |
| Sub-processor BAA active | 7 of 7 BAAs active | 6 of 7 (OpenAI in flight) | OK |
| ZDR contracts active | 2 of 2 (Anthropic, OpenAI) | 2 of 2 | OK |
| Cloud-vs-TEE LLM ratio | 0% cloud, 100% TEE | 0% / 100% | OK |
| Hallucination-guard refusal rate | 1.2% (24 of 2,011 dictations) | 1.4% (18 of 1,297) | OK |
| Off-hours bulk usage | None detected | None detected | OK |
Cryptographic verification
This report is signed with ML-DSA-65 (FIPS 204). The signature is verifiable against the public key at /docs/arcakey-attestation-pubkeys.json (key id monitoring-2026-q2-1).
Signature (excerpt — full signature in machine-readable section below): ml-dsa-65:ed1abf2c...8c4e Signed by: Randall Ausenhus, ArcaKey AI Inc., on 2026-05-01T08:32:14Z Verifier counter-signature: [Verifier Name], on 2026-05-01T11:47:02Z
The full report runs 8–14 pages depending on findings; includes Appendix A (sub-processor documentation template), Appendix B (Verifier methodology certificate), and Appendix C (machine-readable monitoring observations in JSON for the customer's own audit chain).
Start your own monitoring
Onboarding takes 5–8 minutes. Audit customers receive 90 days of Monitoring Pro at no additional charge.