Research
XenLook Compliance Portfolio — Public Self-Assessment and Transparency Index
An index of CSA, IMDA, Observatory, WCAG, OECD, C2PA, and regional ConvAI self-checks. Verifiable public evidence only—not certification claims.

Figure 1. Visual only—not evidence for regulatory claims.
Abstract
XenLook operates cloud controls, AI governance, web security, accessibility, media provenance, and conversational-AI transparency as separate layers, each with self-assessment, public statements, and re-verifiable HTTP/portal evidence. This article is the index (hub) for the June–August 2026 engineering blog series. We deliberately avoid language that reads as “certified” or “officially listed” where only self-assessment applies.
1. Introduction
“Compliance” is often compressed into a single badge. In practice, CSA STAR, IMDA AI Verify, Observatory HTTP grades, WCAG, OECD alignment, C2PA signing, and regional ConvAI duties differ in what is measured, how often it must be re-checked, and acceptable marketing wording.
This portfolio helps readers find which layer to verify where.
2. Layer model
[Edge · transport] Observatory A+ · Site Security · TLS/CSP
[Cloud · ops] CSA STAR Level 1 (self-assessment · registry listing)
[AI · studios] IMDA AI Verify self-assessment · OECD alignment statement
[Product · a11y] WCAG 2.2 AA partial conformance statement
[Media provenance] C2PA signing pilot · XMSE multilayer stack
[ConvAI · regions] JP · EU · US self-check summaries
Figure 2. Logical layers. PASS on one layer does not imply another.
3. Public engineering blog index
The blog index sorts by date descending. This table is a topic index.
4. Marketing wording matrix
| Area | Allowed | Not allowed |
|---|---|---|
| CSA STAR | Registry listing · L1 self-assessment | SOC 2 / ISO certification |
| IMDA AI Verify | Self-assessment complete | IMDA certified / listed |
| Observatory | HTTP A+ profile (snapshot) | No-breach guarantee |
| WCAG | Partial conformance | Full certification |
| OECD | Alignment statement | OECD certification |
| C2PA / XMSE | Signing applied · pilot · public verify UI | Trust List listing · Generator conformity complete |
| US ConvAI | FTC · NIST · state law posture | Federal AI certification |
5. Five-minute reproducibility (recommended)
Canonical: trust/facts · Index: trust-reproducibility-hub
| Step | Action | Expected outcome |
|---|---|---|
| 1 | Open trust/facts | Roster layers + claimStatus glossary |
| 2 | Pick a guide from reproducibility hub | C2PA · SIGNAL · compliance · roster |
| 3 | Follow the guide table (≤6 steps) on public HTTPS origins | Browser or curl -sI 200 |
| 4 | Cross-check ai-certification | Matches this portfolio index |
| 5 | Treat Observatory · Site Security as dated snapshots | Re-measure when needed |
| 6 | Read C2PA/XMSE · SIGNAL pilot limits | No overclaiming |
6. Limitations
- This hub is not legal advice.
- Internal audit scripts and repository paths are not published.
- June snapshots are historical; for C2PA/XMSE prefer the August XMSE article and portal.
References
- XenLook AI certification hub. https://xenlook.com/ai-certification
- XenLook Site Security. https://c2pa.xenlook.com/security
- CSA STAR — see compliance-csa-star-2026-06.
- IMDA AI Verify. https://aiverifyfoundation.sg
- OECD AI Principles. https://www.oecd.org/en/topics/sub-issues/artificial-intelligence
- C2PA. https://c2pa.org
Author Ki-Yeon Nam — XenLook Compliance
Editorial Jia · Sena · Ethan
Review XENLOOK Publication Ethics