Sector policy packs
How Threxen ships each regulated framework as a first-class control plane — detections, containment rules, evidence formats, and reporting cadences tuned to the regulator that matters.
A policy pack is a governed bundle: the detections that fire, the containment rules that run, the evidence formats produced, and the reporting cadence the regulator expects. Five packs ship today — HIPAA, PCI-DSS 4.0, FedRAMP Moderate, DORA, and NIS2 — and they are not retrofitted bolt-ons. Each pack was authored against the named framework’s primary controls, and every Verdict the agents emit is bound to the pack it will be reported under.
Regulated tenants run with at least one pack pinned and audited continuously. PHI access boundaries, BAA-grade isolation, and audit trails across covered-entity tenants are what HIPAA ships; PCI-DSS ships CDE segmentation, card-data-flow whitelisting, and key-evident forensic replay of every containment; FedRAMP brings US-only data egress, FIPS-validated key envelope, and continuous-control reporting aligned to NIST 800-53; DORA supplies the ICT-risk register, third-party-provider incident timelines, and operational-resilience testing posture EU financial entities need; NIS2 covers essential-entity reporting timelines, supply-chain risk register, and sector-specific escalation policies.
A pack is upgraded like a dependency — versioned, change-logged, and shipped with the audit log of who enabled it, when, and against which tenant. If your regulator changes the rule, we ship the rule; you do not re-architect your tenant.