Compliance

Honest compliance, per pipeline stage.

A curated snapshot of the Verimap pipeline across TISAX AL-3, ADAS-grade, and EU data sovereignty — what is signed off today, what is in assessment scope, and which regions each ingest, verify, and patch stage runs in. This page replaces the trust-strip claims and is the source of truth a procurement lead reads before a pilot.

Current control register
The honest state, per pipeline stage.

Verimap's compliance posture is described here the way an OEM procurement team expects — by the pipeline stage the controls apply to, against the bar the partner is held to, and in the region that code actually runs. Statuses are loaded from the current server-side control register; evidence remains presentation copy so it cannot silently become a certification claim.

  • Ingest — Live traffic and fleet-telematics observations arrive as one POST per probe, schema-versioned per source.
  • Verify — The agent swarm flags drifted segments, cross-checks each flag against a second evidence class, and recomputes partner routes.
  • Patch — Verified, HMAC-signed delta bundles reach the OEM — newest-first, audit-traceable.

Loading the current stage posture…

What each axis means
  • TISAX AL-3Trusted Information Security Assessment Exchange — the bar our OEM customers are held to for prototype handling, supplier exchange, and data-center access control.
  • ADAS-gradeISO 26262-aligned process for segment-change arbitration and patch signing. Same ASIL boundary class used for OEM ADAS map compilers.
  • EU data sovereigntyWhere each stage actually runs. EU-only by default; non-EU regions are opt-in and contract-bounded.

Values are operational posture signals, not a substitute for a customer-specific assessment or contract. The stage register was last refreshed at the time shown above.

Observed operational activity

Pipeline activity, with its evidence.

This read-only view summarises persisted Ingest receipts and attempts, Verify outcomes and metrics, and Patch metrics and artefacts. LIVE requires exact LIVE provenance inside the current window: 30 minutes for Ingest and 24 hours for Verify and Patch. Other origins and older timestamps remain visible. Patch artefacts count as LIVE only when a signature is present. This activity view is not a certification or general readiness assessment.

Loading persisted pipeline evidence…

Observed Ingest, Verify and Patch activity, with persisted evidence origin, outcome and timestamps.
StageActivityPersisted evidence by origin
Ingest
UNKNOWN

30-minute window

Waiting for the evidence snapshot…

Verify
UNKNOWN

24-hour window

Waiting for the evidence snapshot…

Patch
UNKNOWN

24-hour window

Waiting for the evidence snapshot…

Ingest contract and source evidence

Source-type support

The ingest API accepts all three event types. API input support is separate from a connector selection or a qualifying recent LIVE receipt; only LIVE is current operational evidence.

Loading current source and connector evidence…

Traffic feed

traffic-feed

POST /api/ingest · traffic[]

Accepted by ingest API

Connector selection catalogue

Loading connector selections…

Current source telemetry

Loading telemetry…

Fleet telematics

fleet-telematics

POST /api/ingest · fleet[]

Accepted by ingest API

Connector selection catalogue

Loading connector selections…

Current source telemetry

Loading telemetry…

EU27 source readiness

Where the evidence is live, selected, or still unverified.

This is an operational source matrix, not a coverage promise. Every row is retained so an OEM team can see the full EU27 boundary; only successful connector receipts can move a territory to LIVE, and the current connector selection is shown separately from ingestion evidence.

For OEM and fleet-operator teams

Share what your team needs to evaluate.

Describe your use case, integration requirements and technical questions. Sending a request does not confirm an evaluation, pilot or partnership.