Compliance Overview
TrueEntropy is designed for regulated industries. Our compliance framework covers gambling (UKGC), statistical verification (NIST), information security (ISO 27001), and data protection (UK GDPR). Every request produces an auditable provenance certificate powered by QuBitLang.
Available Compliance Packs
UKGC RTS 7
Full compliance with Remote Technical Standards requirement 7 for random number generation in gambling. Includes methodology reports, testing summaries, and QuBitLang circuit source audit documentation.
- RNG methodology report
- Testing summary with 7/7 NIST pass
- QuBitLang circuit source audit
- Dedicated compliance dashboard
NIST SP800-22
Continuous verification against the complete NIST SP800-22 statistical test suite. All 15 tests run on every entropy batch before pool entry. Results available in real-time via dashboard and API.
- 7/7 test suite (frequency, runs, FFT, etc.)
- Dieharder extended suite (114 tests)
- Continuous monitoring via AI QA pipeline
- Downloadable test reports
Provenance Certificates
Every API response includes a certificate_id in the metadata. This ID links to a full provenance certificate containing:
- QuBitLang circuit - The exact circuit and version used to generate the entropy
- Quantum backend - Which IBM quantum processor executed the circuit
- NIST verification - Statistical test results for the entropy batch
- Cryptographic hashes - SHA-256 hashes at each stage (raw → processed → delivered)
- Public verification - Any certificate can be verified at trueentropy.net/verify
ISO 27001 Alignment
TrueEntropy's infrastructure and processes are aligned with ISO 27001 information security management standards. Control mapping documentation is available for Business and Enterprise tier customers via the Compliance Centre in the dashboard.
UK GDPR
TrueEntropy is designed with data minimisation by design. No personally identifiable information enters the entropy generation pipeline. Only compiled QuBitLang circuits are transmitted to quantum hardware - no customer data. Full details in our Privacy Policy.