Legal
Evidence-backed compliance status. We publish our actual posture, not aspirational claims.
Last updated: April 25, 2026
This page reflects ORA’s actual compliance posture as of April 25, 2026 — backed by code controls, not aspirational statements. Per FTC substantiation guidance (March 2026), we only mark a framework “Compliant” when the controls are implemented and verifiable. Status will be updated as each control is completed.
| Framework | Jurisdiction | Status | Evidence / Measures |
|---|---|---|---|
| PIPEDA | Canada | Implementation in progress | Privacy policy published. Server-side auth, data retention enforcement, and access/export/delete workflows under active development. |
| CASL (Canada's Anti-Spam Legislation) | Canada | Compliant | Express consent for all communications. Unsubscribe mechanisms operational. |
| GDPR | EU/EEA | Partial — Canada adequacy applies | DPA available, data subject rights documented. Server-side enforcement of retention and deletion workflows pending. Canada has EU adequacy decision. |
| FTC AI enforcement posture | United States | Partial | AI disclosures implemented in UI (lobby, chat badges). API-level headers deployed. Claims require ongoing substantiation as production evidence accumulates. |
| EU AI Act — Article 50 Transparency | European Union | Partial — deadline August 2, 2026 | UI disclosure and API headers implemented. Machine-readable labeling and export-level provenance metadata in progress. |
| Colorado SB 24-205 | Colorado, USA | In progress — deadline June 30, 2026 | Risk assessment page published. Consequential-decision gate, impact assessment object, and consumer correction/appeal workflows under development. NIST AI RMF alignment documented. |
| Texas TRAIGA | Texas, USA | Partial — active since January 2026 | Prohibited uses enforced via Acceptable Use Policy. NIST AI RMF alignment in progress for affirmative defense. |
| California AI Transparency Act (SB 942) | California, USA | Preparing — effective August 2026 | AI-generated content disclosure in UI. Machine-readable watermarking roadmap under development. |
| NIST AI RMF 1.0 | Voluntary (US safe harbor) | Mapping in progress | Govern/Map/Measure/Manage narrative published. Executable controls and evidence register under active development. |
| SOC 2 Type II | Trust framework | Roadmap — target 2027 | Security policy, access controls, and audit logging implemented. Formal SOC 2 audit engagement planned. |
X-AI-Generated disclosure headers./pulz/audit with CSV export for compliance documentation.POST /api/pulz/consumer-rights accepts access, correction, deletion, and appeal requests with 30-day SLA tracking.