The herd is the market. The DoD is the halo.
| Segment | Frameworks | Delivery | Role |
|---|---|---|---|
| The herd — volume | SOC 2 · HIPAA · PCI-DSS · ISO 42001 · GDPR · EU AI Act | Managed BYOC VPC (their account, their keys) | revenue + growth |
| Sovereign — halo | DoD IL5 · CMMC · air-gap | Shipped software (they run it) | margin + credibility |
The volume is in the regulated commercial herd. The DoD tier is the trust anchor that closes the commercial sale — nobody selling into healthcare or fintech has a DoD-hardened governance story. You do. And it's one product on one dial: the same envelope, dialed from Sovereign down to Regulated or Bolt-on. The commercial buyer inherits the DoD-grade moat — CNSA SHA-384 seal, in-VPC treaty enforcement, dual Recall — with the tier setting the floor for their framework, not the IL5 label or the IL5 price.
Three things a CISO needs. Legation has all three.
End of the questionnaire
A pre-built audit package collapses a six-week security review into a document. You sell de-risking, not software.
A kill switch they hold
The customer can sever the deployment unilaterally — and the operator cannot override it. The single sentence that relaxes a CISO.
Their account, their keys
BYOC: it runs in the customer's own VPC, on their KMS keys, inside their boundary. Sovereignty by construction.
The evidence pack is the vertical-specialization layer.
Same product. Flip the framework, flip the vertical. Two are open land-grabs — new law, no incumbents.
PCI-DSS
Fintech & payments. Card data never persists; "test security regularly" is satisfied by QA-in-VPC.
HIPAA
Healthcare & health-tech. "Minimum necessary" = only projections ever cross the membrane.
GDPR
Anything EU. Data-flow inversion is data-minimisation; residency is structural.
EU AI Act ⚡
Everyone deploying AI in the EU. New law, enforcement ramping, zero deployment-governance answers in market.
ISO 42001 ⚡
Enterprises formalizing AI governance. The first AI management standard — they're just starting to certify.
SOC 2
The default enterprise trust bar. The whole TSC maps to the envelope's mechanisms.