Glossary
The Caisson glossary.
Definitions for the compliance, security, licensing, and AI-infrastructure terms Caisson ships real code against: WORM audit logs, row-level security, token metering, and more.
Compliance & audit (19)
- Append-only audit log
- Audit evidence bundle
- Compliance crosswalk
- Compliance-as-code
- Control-to-code mapping
- Durable outbox
- EU AI Act Article 50
- Evidence receipt
- HIPAA technical safeguards
- OSCAL
- OSCAL export from a TypeScript stack
- RFC 3161 timestamping
- S3 Object Lock
- SOC 2 audit log
- Tamper-evident hash chain
- Transparency log
- WORM audit log
- WORM audit logs for SaaS
- WORM retention policy
Multi-tenancy & security (13)
- Additional authenticated data (AAD)
- BYOK (bring your own key)
- Canonical JSON
- Crypto-shredding
- Envelope encryption (DEK/KEK)
- Fail-closed
- Field-level encryption
- Multi-tenant isolation
- Multi-tenant RLS for compliance
- Per-tenant key derivation (HKDF)
- Row-Level Security (RLS)
- Signed audit anchor
- Token hashing at rest