Quick Start
Get governance controls running in under 5 minutes.How It Works
Governance Flow
- Policy Selection - Default policy or specified by
governance_policyslot - Trust Tier Check - Provider must meet minimum trust tier
- Compliance Check - Provider must have required certifications
- Enforcement - Block, warn, or allow based on policy configuration
- Audit Logging - All decisions are logged for compliance reporting
Core Concepts
Trust Tiers
Providers are categorized into trust tiers based on their compliance posture:| Tier | Description | Use Case |
|---|---|---|
most_trusted | Full enterprise compliance (SOC 2, HIPAA, BAA, ZDR) | Healthcare, financial services |
trusted | Good compliance, may lack some certifications | General enterprise |
sketchy | Limited compliance info available | Development/testing only |
untrustworthy | China-based, subject to national security laws | Always blocked |
Compliance Certifications
| Certification | Description |
|---|---|
| SOC 2 Type II | Security, availability, processing integrity controls |
| HIPAA | Protected health information handling |
| BAA | Business Associate Agreement available |
| ZDR | Zero Data Retention - no training on your data |
| ISO 27001 | Information security management |
| GDPR | EU data protection compliance |
Enforcement Modes
| Mode | Behavior |
|---|---|
hard_block | Request fails with 403 error |
soft_block | Request fails, but logged as violation |
warn | Request proceeds, violation logged |
Shared Responsibility Model
| Responsibility | Case.dev | Customer |
|---|---|---|
| Policy configuration | Provides tools | Configures policies |
| Provider compliance verification | Provides data | Validates for your use case |
| Audit log retention | 30 days | Export for longer retention |
| Regulatory compliance determination | - | Your responsibility |
| Provider BAA execution | - | Your responsibility |
| Data handling by providers | - | Your responsibility |
Provider Compliance Data: We aggregate compliance information from provider documentation, but you should verify certifications directly with providers for your specific regulatory requirements.
Next Steps
Provider Registry
View all providers with their trust tiers and compliance certifications.
Policy Configuration
Create and manage governance policies for your organization.
Audit Logging
Query audit logs and generate compliance reports.
LLM API
Use governance policies with the Chat Completions API.

