Docs / Compliance

Compliance Overview

TrueEntropy is designed for regulated industries. Our compliance framework covers gambling (UKGC), statistical verification (NIST), information security (ISO 27001), and data protection (UK GDPR). Every request produces an auditable provenance certificate powered by QuBitLang.

Available Compliance Packs

UKGC RTS 7

Full compliance with Remote Technical Standards requirement 7 for random number generation in gambling. Includes methodology reports, testing summaries, and QuBitLang circuit source audit documentation.

  • RNG methodology report
  • Testing summary with 7/7 NIST pass
  • QuBitLang circuit source audit
  • Dedicated compliance dashboard

NIST SP800-22

Continuous verification against the complete NIST SP800-22 statistical test suite. All 15 tests run on every entropy batch before pool entry. Results available in real-time via dashboard and API.

  • 7/7 test suite (frequency, runs, FFT, etc.)
  • Dieharder extended suite (114 tests)
  • Continuous monitoring via AI QA pipeline
  • Downloadable test reports

Provenance Certificates

Every API response includes a certificate_id in the metadata. This ID links to a full provenance certificate containing:

  • QuBitLang circuit - The exact circuit and version used to generate the entropy
  • Quantum backend - Which IBM quantum processor executed the circuit
  • NIST verification - Statistical test results for the entropy batch
  • Cryptographic hashes - SHA-256 hashes at each stage (raw → processed → delivered)
  • Public verification - Any certificate can be verified at trueentropy.net/verify

ISO 27001 Alignment

TrueEntropy's infrastructure and processes are aligned with ISO 27001 information security management standards. Control mapping documentation is available for Business and Enterprise tier customers via the Compliance Centre in the dashboard.

UK GDPR

TrueEntropy is designed with data minimisation by design. No personally identifiable information enters the entropy generation pipeline. Only compiled QuBitLang circuits are transmitted to quantum hardware - no customer data. Full details in our Privacy Policy.