Institutional Governance & Regulatory Framework

Regulatory & Legal Compliance

Entity: Solstate LLC Jurisdiction: State of Delaware Active & In Good Standing

01. Delaware Entity Standing & Corporate Existence

Solstate LLC is a limited liability company duly organized, validly existing, and in good standing under the laws of the State of Delaware, United States (formed pursuant to the Delaware Limited Liability Company Act, Title 6, Chapter 18 of the Delaware Code).

Jurisdiction of Organization: State of Delaware, USA
Entity Classification: Technology Holding Company
Corporate Status: Active & Good Standing
Franchise Tax & Annual Filings: Current / Compliant

Solstate LLC maintains full compliance with state franchise requirements, registered office representation, and statutory annual filing obligations in Delaware.

02. Structural Separation & Subsidiary Operational Firewalls

Solstate LLC operates on a decentralized holding company model. Each operating vertical and software subsidiary (such as StayBooked for contractor lead generation and Vox AI for telephony pipelines) maintains:

  • Independent Operational Infrastructure: Distinct database clusters, server hosting nodes, encryption keys, and network VPCs with zero cross-tenant credential sharing.
  • Distinct Terms & Compliance Regimes: Independent end-user terms of service, customer privacy disclosures, and statutory consent collection workflows tailored to each industry sector.
  • Corporate Liability Separation: Parent holding company governance oversight without commingling operational assets or customer transaction data.

03. AI Governance, Safety & Algorithmic Transparency

Our cognitive reasoning and conversational voice architectures (including Agent Brain and Vox AI) are developed and operated in alignment with recognized AI risk management standards, including the NIST AI Risk Management Framework (NIST AI RMF 1.0):

Deterministic Tool Execution & Guardrails AI agents are bound by strictly typed JSON schema validation, deterministic state machines, and bounded execution graphs. No autonomous agent is permitted to execute unbounded financial transfers or destructive database deletions without explicit programmatic bounds.
Automated Audit Tracing & Reasoning Logs Every multi-turn reasoning graph, tool call invocation, and external API emission is immutably logged with cryptographic timestamps for institutional verification and post-execution review.
Human-in-the-Loop Escalation Protocols Out-of-distribution user intents, disputed appointments, or sensitive edge cases immediately trigger automated failovers and reroute conversations to human operator review queues.

04. Telecommunications & Telephony Compliance (FCC, TCPA, CTIA)

Subsidiaries utilizing voice telephony and messaging infrastructure (such as StayBooked and Vox AI) operate in strict adherence to federal and industry telecommunication regulations:

  • Telephone Consumer Protection Act (TCPA): Automated qualification calls and text messages are initiated exclusively upon explicit, unambiguous consumer consent submitted through verified landing page checkboxes.
  • A2P 10DLC Carrier Registration: All messaging campaigns and origin numbers are registered and verified through The Campaign Registry (TCR) under certified brand and campaign trust scores.
  • STIR/SHAKEN Caller ID Authentication: Outbound SIP voice streams maintain full cryptographic caller ID attestation (A-level where applicable) to eliminate spoofing and ensure transparent caller identification.
  • Instant Opt-Out / STOP Processing: Inbound "STOP," "UNSUBSCRIBE," or verbal revocation requests are processed automatically and instantaneously across all messaging and voice buffers.

05. Healthcare & Clinical Data Security (HIPAA Controls)

For specialized clinical reception systems (such as FrontDesk), technical safeguards are architected to satisfy HIPAA Security and Privacy Rule requirements:

  • End-to-end data encryption using AES-256 for data at rest and TLS 1.3 for data in transit;
  • Role-based access control (RBAC) and least-privilege administrative access;
  • Encrypted, isolated patient intake vaults with strict audit-logging for every PHI read and write event;
  • Business Associate Agreement (BAA) execution frameworks for healthcare enterprise clients.

06. Export Controls & Sanctions Compliance (OFAC & EAR)

Solstate LLC enforces strict adherence to United States export control regulations, including the Export Administration Regulations (EAR) administered by the U.S. Department of Commerce and economic sanctions programs administered by the Office of Foreign Assets Control (OFAC) of the U.S. Department of the Treasury.

Our software architectures and intellectual property may not be downloaded, exported, re-exported, or licensed to any entity or individual located in embargoed jurisdictions or listed on the Specially Designated Nationals (SDN) list or Entity List.

07. Law Enforcement, Subpoena & Regulatory Intake Protocol

Solstate LLC cooperates with valid, formal legal requests from judicial, governmental, and regulatory authorities. All subpoenas, court orders, or civil investigative demands must be formally served and addressed to our corporate entity.

Dedicated Regulatory & Subpoena Intake: compliance@solstate.us / legal@solstate.us
Response SLA for Official Service: < 24 business hours
Verification Standard: All requests must specify the legal basis, statutory authority, official agency credentials, and precise scope of the inquiry.