Tuttify Carbon · Compliance Engine

Pick a framework. Eight engines reshape every artifact downstream.

Every framework you tick on Tuttify Carbon's Smart Intake doesn't just decorate the cover page. It propagates through eight downstream engines — biasing intensity dials, swapping in framework-specific agents, spawning new artifacts, and forcing override locks when the cost of getting it wrong includes criminal liability.

15+
Active cues
8
Engines per cue
2
Independent dials
5
Forced overrides
The catalog

Every framework that puts you in front of an auditor — pre-wired.

The catalog grew from 12 to 15 with the addition of iso_42001, nist_ai_rmf, and the split of fda_samd from HIPAA. Every cue carries documented downstream effects — including its strictness rank and intensity bias.

Rank 6Criminal-penalty
ITAR / EAR

Export controls. Forces safety_intensity high and thorough gate visibility — cannot be silently weakened.

Rank 6Criminal-penalty
CJIS

Criminal Justice Information Services. Forced override engages automatically.

Rank 5Federal control depth
FedRAMP / NIST 800-53

Control families AC · AU · CM · CP · IA · IR · RA · SC · SI · CA. Default template targets FedRAMP Moderate; High and IL5 are configurable. Artifacts: SSP, POA&M, CRM, ConMon plan, SAR-ready evidence stubs by family.

Rank 4Patient privacy
HIPAA

PHI handling sections, BAA scope, audit-log retention horizons (164.312(b)), breach-response artifacts (164.408 / 164.410). Control citations to 164.308–164.316 throughout.

Rank 4Patient safety · SaMD
FDA SaMD

IEC 62304 software lifecycle (Class A/B/C). ISO 14971 risk management — hazards, harms, probability, severity. 21 CFR Part 820 design controls. 2023 FDA Cybersecurity Premarket Guidance + SBOM. Risk register switches to 14971 structure; artifacts shape for a 510(k) DHF.

Rank 4Health-info security framework
HITRUST CSF

CSF v11 control specifications mapped across the 19 categories. Inheritance-tier reasoning (System / Customer / Vendor). MyCSF-shaped evidence stubs and r2-assessment scope statement.

Rank 3High audit cadence
SOX / PCI-DSS

Cardholder Data Environment diagram, segregation-of-duties tables, change-control records.

Rank 3Financial institutions
GLBA

Safeguards rule mapping, NPI inventory, vendor-risk artifacts.

Rank 3AI Governance
ISO / IEC 42001

Spawns a dedicated ai-governance.md artifact. AIMS scope, AI-impact assessment, lifecycle responsibilities.

Rank 3AI Governance
NIST AI RMF

Govern · Map · Measure · Manage tagging on every AI-touching requirement.

Rank 2Trust services criteria
ISO 27001 / SOC 2

TSC mapping for Security, Availability, Confidentiality and Privacy. Per-control narrative stubs (CC6.1 access control, CC7.2 monitoring, etc.) keyed to your system description.

Rank 2Privacy
GDPR

Article 30 records, DPIA triggers, data-subject rights flow.

Rank 2Privacy
CCPA / CPRA

Consumer rights flows, opt-out plumbing, sensitive PI tagging.

Rank 2Education / Minors
FERPA / COPPA

Student-record protection, parental consent flow.

Rank 1Accessibility
Section 508 / WCAG

A11y acceptance criteria injected into every UI requirement.

Rank 0Baseline
None

The synthetic baseline. Carbon still ships PRD, SRD, threat model — without framework-specific overlays.

The fan-out

Every checkbox propagates. Nothing is hand-waved.

Every flag you select is wired through a documented effect map. Nothing implicit. Nothing hand-waved. You can audit the bias map in source as derived_defaults.py::_REGULATORY_INTENSITY_BIAS.

01
Engine
Intake validator

Validates the cue against the project shape. Surfaces missing intake answers required by the framework.

02
Engine
Derived defaults

Computes the project profile: gate visibility, tone register, RQS weighting, audit cadence.

03
Engine
Recipe resolver

Picks the agent roster. A HITRUST run brings 8+ agents. A landing page brings 4.

04
Engine
Intensity dials

Sets compliance_intensity and security_intensity independently. Each acts as a floor — never weaker than baseline.

05
Engine
Compliance writer

Modifies compliance-risks.md and risk-register.csv. May spawn entirely new artifacts (e.g. ai-governance.md).

06
Engine
Threat-model writer

Adds attacker payload sections and framework-specific abuse cases to threat-model.md.

07
Engine
Template extractor

Pulls the framework's required section structure into the output template. No ad-hoc layouts.

08
Engine · Override
Forced override

For Rank-5+ frameworks: locks safety_intensity=high and thorough gate visibility. Cannot be silently weakened.

Two independent dials

Compliance and Security don't share a dial.

The legacy single safety dial was split deliberately. A FedRAMP build needs maximal security intensity — but a Section 508 + GDPR run needs compliance intensity dialed up without the threat model getting heavier than the scope warrants.

Each framework you tick carries a documented bias on both dials. The biases stack. The result is the higher floor — never weaker than any single framework would have demanded.

Framework
Compliance intensity
Security intensity
FedRAMP / NIST
HIGH
MAX
FDA SaMD
MAX
HIGH
HIPAA
HIGH
HIGH
SOX / PCI-DSS
HIGH
MED
ISO 42001
HIGH
MED
ISO 27001 / SOC 2
MED
MED
Section 508 / WCAG
MED
LOW

Floors only · stacked frameworks raise the floor, never lower it.

Forced override

For criminal-penalty frameworks, there is no soft path.

If your build touches HIPAA, FDA SaMD, FedRAMP/NIST, HITRUST, ITAR/EAR or CJIS, Carbon forces safety_intensity=high and the Intervention Budget to thorough — every gate visible. This override cannot be silently weakened by a less-strict base rule elsewhere in the cue mix.

When override engages
LOCKEDsafety_intensity = high
LOCKEDIntervention budget = thorough
VISIBLEAll five gates G1–G5 surfaced

What can't happen
  • A lighter framework in the mix downgrading the FedRAMP floor.
  • A "fast" run hiding G3 or G4 review for a HIPAA build.
  • A silent demotion of intensity by another engine downstream.
Submission-ready by construction

The reviewer doesn't get a doc. They get receipts.

Provenance
Every claim links back

Provenance pills are first-class UI. Every requirement, every framework citation, every diagram traces to the intake answer, supporting document, or generated artifact that produced it.

Tamper-evident
Hash-chained history log

Every state-changing event is appended to a hash-chained log. carbon audit verify greens the chain. The tamper-demo reds it. Reviewers see the seal.

RQS
Requirements Quality Score

Deterministic. Not LLM-graded. EARS pattern detection + INCOSE rule checking. The reference demo lifts from 0.82 to 0.93 after one G4 refinement — visible, audited, repeatable.

Bring us your hardest regulatory cue mix.

FedRAMP + HIPAA + ISO 42001 in the same build? That's a working session. We'll run it through Carbon and walk you through the bundle that comes out.