Security & Safety

Frontier AI is now more secure than most of the laptops it runs on.

That’s a real claim, and we don’t make it lightly. Every major frontier-model provider — Anthropic, OpenAI, Perplexity, xAI — publishes a public trust center, ships an enterprise-grade tier, and meets the certifications federal agencies, healthcare systems, and ISO-certified manufacturers require of their own infrastructure. This page covers what that buys you when you start running export-control data through any of them, why we recommend Claude for the actual compliance work, and the four guarantees ExChek adds on top.

The four trust centers

Pick a frontier provider. We’ll run on it.

ExChek isn’t locked to one model. The plugin works inside any major frontier harness, so you inherit whichever provider’s security posture you already trust. Click through to read each provider’s scope letters, audit reports, and continuous-monitoring evidence yourself.

The shared bar

What enterprise frontier tiers commit to.

Different providers cover slightly different scopes, but the bar below is what most enterprise frontier tiers meet today. If your compliance team has a checklist of certifications they require before approving a new vendor, this is the list they’ll usually be holding.

HIPAA

Protected health information handling

SOC 2 Type II

Security, availability, confidentiality

ISO 27001:2022

Information security management

ISO/IEC 42001:2023

AI management system

FedRAMP High

U.S. federal high-impact data

UK Cyber Essentials

UK government baseline

Specific scope, monitoring, and report availability vary by provider. Always confirm at the trust center linked above.

Why we recommend Claude

On the security side, the providers are roughly even. On agentic capability, they’re not.

Trust posture is table stakes — all four major providers ship enterprise-grade tiers. Where ExChek picks a side is narrower and more specific: agentic capability for enterprise workflows. Claude is currently ahead on the exact things a compliance agent has to do well — reading long technical documents, calling tools reliably, stringing multi-step reasoning together, and not making things up under pressure.

01

Leads on tool use and computer use.

Claude Opus 4.7 hits 77.3% on MCP-Atlas (scaled tool use) and 78% on OSWorld-Verified (computer use) — both ahead of the field. Compliance work is tool-heavy: pull eCFR, screen CSL, generate Word, sign the audit log. Claude does that better than anything else right now.

02

Wins on long-context and document reasoning.

Opus 4.7 leads on GraphWalks (long-context) and posts 80.6% on OfficeQA Pro — 23+ points ahead of the next model on document reasoning. CFR Part 774 is hundreds of pages. That’s the work.

03

Constitutional AI, not bolt-on filters.

Claude is the only frontier model trained from the ground up on a constitution — not prompted into safety after the fact. For high-stakes regulatory work, that means fewer surprises and reasoning that holds up under audit.

See the head-to-head numbers on our Accuracy page →

What ExChek promises you

On top of your frontier provider’s security, four guarantees from us.

Your frontier provider secures the model and the platform. ExChek makes sure the workflow stays yours, stays defensible, and never makes a decision you didn’t approve. Belt and suspenders.

Promise 1

Your data stays where you put it.

Sensitive lookups — customer names, part specs, denied-party checks — happen on your machine, inside the frontier-model session you already control. We don’t copy your data to a server we run. If your IT lead asks “where does this go?” the answer is short: nowhere new.

Promise 2

Nothing is watching you.

The plugin doesn’t send us usage stats, error reports, or sample queries. We can’t see what parts you’re shipping or where. If you uninstall, we don’t even know that. The whole codebase is public — you (or your IT person) can read it.

Promise 3

Records you can hand to a regulator.

Every classification, screening, and memo gets a sealed timestamp linked to the one before it. If anyone alters a record after the fact, the seal breaks — and the break is obvious. That’s the kind of paper trail BIS expects on the five-year recordkeeping rule.

Promise 4

You sign every decision. Not the AI.

ExChek never auto-files anything, never auto-approves a classification, and never puts the AI’s name on the memo. You read the reasoning, you check the citations, you sign off. If a regulator asks who made the call, you can answer with one name — yours.

What you actually get

What this means on a Tuesday morning at your shop.

You ship to Germany. A customer asks for a CCATS letter or an EAR99 self-classification. You run the request through ExChek. Three things happen automatically:

  • Your part data never leaves the platforms you already trust. Your frontier provider for the inference, your laptop for the lookup, your file system for the memo.
  • The result is signed and chained. If a regulator ever asks you to prove the memo wasn’t altered after the fact, you can.
  • You can hand it to your lawyer. Citation-backed reasoning + tamper-evident log = defensible documentation. The kind of paper trail BIS expects on five-year recordkeeping.

Run it on a part. See for yourself.

Five-minute install. No credit card. No data leaves your laptop except what you send to the frontier model you already chose.