<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>Bidda Sovereign Intelligence - Latest</title>
    <link>https://bidda.com/</link>
    <description>Insights and material updates from the Bidda compliance intelligence registry. 9,964 source-verified regulatory nodes across 39 sovereign pillars. Newest first.</description>
    <language>en-us</language>
    <atom:link href="https://bidda.com/feed.xml" rel="self" type="application/rss+xml" />
    <lastBuildDate>Fri, 26 Jun 2026 14:59:43 GMT</lastBuildDate>
    <generator>Bidda generate-site-data.js</generator>
    <ttl>1440</ttl>
    <image>
      <url>https://bidda.com/assets/bidda-logo.png</url>
      <title>Bidda Sovereign Intelligence - Latest</title>
      <link>https://bidda.com/</link>
    </image>
    <item>
      <title>Run Ledger: a signed, tamper-evident record of a whole agent task or conversation</title>
      <link>https://bidda.com/changelog#20260626</link>
      <guid isPermaLink="true">https://bidda.com/changelog#20260626</guid>
      <description>A single signed record covers one decision. The new Run Ledger covers a whole task or conversation. Connect a bot or agent (for example a support bot or chat widget), open a run, and record one entry per turn as it consults rules and answers the person, then seal the run into a single signed run receipt that covers every turn. Each entry locks in the one before it, so nothing can be added, removed or re-ordered afterwards without it showing, and the user&apos;s input can be stored as plain text or only as a private hash that never leaves your process. Anyone you hand the receipt to can verify it against our public key with no Bidda account. It is available on the Run Ledger tab at /attest, and through four new tools (open_run, record_run_entry, seal_run, get_run) on the Bidda MCP server and the bidda-shield SDK, which the bidda-shield package wraps in a one-line &quot;with shield.run(...) as run&quot; helper. Opening, recording and sealing use your Bidda key and a free trial counts; verifying a sealed receipt is free.</description>
      <pubDate>Fri, 26 Jun 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Engineering</dc:creator>
      <category>Changelog · Platform</category>
    </item>
    <item>
      <title>Verify any signed record yourself, and signing-key rotation that never breaks past records</title>
      <link>https://bidda.com/changelog#20260621</link>
      <guid isPermaLink="true">https://bidda.com/changelog#20260621</guid>
      <description>You can now check a Bidda signed record on your own, with no Bidda account, using a new page at /verify-attestation that runs entirely in your browser. Paste a record and it confirms the digital signature and that nothing in the record was changed. The exact method is published at /.well-known/bidda-attestation-spec.md, and command-line checkers for Node and Python are included for auditors who prefer the terminal. We also rotate our signing key from time to time as good security practice. Every key we have ever used to sign records stays published at /api/v1/attest/keys, so a record signed by an older key keeps verifying for as long as you hold it. Rotating our signing key changes only which key signs new records; it does not affect any record already issued, and it has no effect on your API key, your plan, or your trial, which are a separate system.</description>
      <pubDate>Sun, 21 Jun 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Engineering</dc:creator>
      <category>Changelog · Trust</category>
    </item>
    <item>
      <title>MCP server and Python SDK expanded to fourteen tools, including the new self-serve compliance tools</title>
      <link>https://bidda.com/changelog#20260620</link>
      <guid isPermaLink="true">https://bidda.com/changelog#20260620</guid>
      <description>The Bidda MCP server at https://bidda.com/mcp and the bidda-shield Python SDK now expose fourteen tools. Ten are free with no API key: the existing discovery and runtime-intelligence tools plus a new browse_topics tool that lets an AI assistant explore the registry by cross-cutting topic. Four are for subscribers and use your Bidda key (a free trial counts): compare_jurisdictions (see how jurisdictions differ on a topic, including where their numbers differ), create_attestation (save a signed record of which rules a decision relied on), point_in_time (what a rule said at a past date), and watch_changes (email or webhook alerts when a watched source changes). The downloadable SDK and the published bidda-shield package on PyPI were updated to match, so an autonomous agent can now run the full set programmatically.</description>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Engineering</dc:creator>
      <category>Changelog · Developers</category>
    </item>
    <item>
      <title>New self-serve compliance tools: signed records, point-in-time history, change alerts, jurisdiction comparison, and topic browsing</title>
      <link>https://bidda.com/changelog#20260620</link>
      <guid isPermaLink="true">https://bidda.com/changelog#20260620</guid>
      <description>Bidda now ships a set of self-serve tools for compliance teams. Signed Records at /attest let you save a time-stamped, digitally signed record of which rules a person or AI agent relied on for a decision, and let anyone confirm later that the record has not been changed. Point-in-time records capture what a rule said on a specific past date, tied to its entry in our public history. Change Alerts at /alerts let you watch the rules and pillars that matter to you and get an email or webhook when their primary source changes. Compare Jurisdictions at /compare lets you search a topic and see how different countries address it side by side, including where their numeric thresholds differ, such as a breach-notification deadline of 72 hours in one place and 30 days in another (it shows the real numbers and never ranks which is stricter). Browse by Topic at /topics is a cross-cutting view that groups rules by subject across every pillar and jurisdiction, while your existing pillars stay exactly as they are. The signed-record and alert tools are available to subscribers, including during a free trial.</description>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Engineering</dc:creator>
      <category>Changelog · Platform</category>
    </item>
    <item>
      <title>Bidda x CISA position published: CPG crosswalk, Secure by Design attestation, free-for-defenders catalogue</title>
      <link>https://bidda.com/changelog#20260608</link>
      <guid isPermaLink="true">https://bidda.com/changelog#20260608</guid>
      <description>Bidda now publishes a consolidated position against the three public-trust surfaces the Cybersecurity and Infrastructure Security Agency maintains for software vendors and defender tooling. The hub at /cisa links to a bidirectional crosswalk of CISA&apos;s eight Cybersecurity Performance Goals against Bidda&apos;s executable compliance nodes at /cisa/cpg-crosswalk, a public attestation against each of the seven Secure by Design Pledge goals with supporting evidence per goal at /cisa/secure-by-design, and a catalogue of the no-cost Bidda capabilities that are free at point of use for federal agencies, state, local, tribal and territorial governments, and operators of critical infrastructure at /cisa/free. The homepage carries a &quot;Built to CISA&apos;s public-trust standards&quot; band that links into the same position. JS-free plain-text mirrors of each of the four CISA pages were also added so AI crawlers that do not execute JavaScript can read the full content.</description>
      <pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Engineering</dc:creator>
      <category>Changelog · Trust</category>
    </item>
    <item>
      <title>Privacy policy v2.2: United States federal, state, SLTT and critical-infrastructure user posture documented</title>
      <link>https://bidda.com/changelog#20260608</link>
      <guid isPermaLink="true">https://bidda.com/changelog#20260608</guid>
      <description>The privacy policy now includes a dedicated section 11a covering data-handling for users in the United States. The section names the rights granted to residents of the seventeen United States states with comprehensive consumer-privacy statutes (Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Indiana, Tennessee, Florida, Delaware, New Hampshire, New Jersey, Kentucky, Maryland and Minnesota), describes the posture Bidda holds for federal agencies and state, local, tribal and territorial governments and operators of critical infrastructure, and documents the cross-border transfer mechanism in place with sub-processors. Effective 2026-06-08, v2.2.</description>
      <pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Engineering</dc:creator>
      <category>Changelog · Trust</category>
    </item>
    <item>
      <title>DORA Compliance in 2026: ICT Risk, Incident Reporting, and Third-Party Concentration for EU Financial Entities</title>
      <link>https://bidda.com/insights/dora-compliance-2026-ict-risk-third-party</link>
      <guid isPermaLink="true">https://bidda.com/insights/dora-compliance-2026-ict-risk-third-party</guid>
      <description>DORA (Regulation EU 2022/2554) replaces the patchwork of ICT outsourcing guidance for EU financial entities with a single framework covering ICT risk management (Article 5), incident classification and reporting (Articles 17-23), digital operational resilience testing including TLPT (Articles 24-27), and ICT third-party concentration risk (Articles 28-44). The Bidda registry maps every obligation to its primary Article and crosswalks each to the corresponding NIST 800-53, ISO/IEC 27001, and APRA CPS 234 controls.</description>
      <pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Sovereignty Engineering Group</dc:creator>
      <category>Insights · Regulatory Operations</category>
    </item>
    <item>
      <title>NIS2 Directive Compliance: A 2026 Field Guide for Essential and Important Entities</title>
      <link>https://bidda.com/insights/nis2-directive-essential-important-entities-2026</link>
      <guid isPermaLink="true">https://bidda.com/insights/nis2-directive-essential-important-entities-2026</guid>
      <description>NIS2 (Directive EU 2022/2555) replaces the 2016 NIS1 framework, expanding cybersecurity obligations across eleven sectors of essential entities and seven sectors of important entities. The directive sets a 24-hour early-warning, 72-hour incident notification, and one-month final-report cadence under Article 23, holds management bodies personally accountable under Article 20, and exposes essential entities to administrative fines of up to €10 million or 2% of global annual turnover.</description>
      <pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Sovereignty Engineering Group</dc:creator>
      <category>Insights · Cybersecurity &amp; Compliance</category>
    </item>
    <item>
      <title>MiCA Compliance for Crypto-Asset Service Providers: Authorisation, Whitepapers and Market Abuse in 2026</title>
      <link>https://bidda.com/insights/mica-crypto-compliance-casp-2026</link>
      <guid isPermaLink="true">https://bidda.com/insights/mica-crypto-compliance-casp-2026</guid>
      <description>MiCA (Regulation EU 2023/1114) is the first comprehensive EU framework for crypto-assets. Title II covers crypto-asset issuance and whitepaper requirements. Title III governs asset-referenced tokens (ARTs). Title IV governs e-money tokens (EMTs). Title V regulates crypto-asset service providers (CASPs) - authorisation, prudential, conduct, and travel-rule obligations. Title VI prohibits insider dealing and market manipulation in crypto-assets. The Bidda registry maps every operative Article to its primary citation and to the corresponding FATF, EBA and ESMA technical standards.</description>
      <pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Sovereignty Engineering Group</dc:creator>
      <category>Insights · Crypto &amp; Sovereign Finance</category>
    </item>
    <item>
      <title>ISO/IEC 42001 AI Management System: The 2026 Implementation Guide for Production AI</title>
      <link>https://bidda.com/insights/iso-iec-42001-ai-management-system-2026</link>
      <guid isPermaLink="true">https://bidda.com/insights/iso-iec-42001-ai-management-system-2026</guid>
      <description>ISO/IEC 42001:2023, published in December 2023, is the world&apos;s first international AI management system (AIMS) standard. It mirrors the structure of ISO/IEC 27001 - leadership (Clause 5), planning (Clause 6), support (Clause 7), operations (Clause 8), performance evaluation (Clause 9), and continual improvement (Clause 10) - with an AI-specific control catalogue in Annex A. The Bidda registry maps every clause to its EU AI Act and NIST AI RMF crosswalk, and to the certification-evidence pattern that an external auditor expects.</description>
      <pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Sovereignty Engineering Group</dc:creator>
      <category>Insights · AI Architecture</category>
    </item>
    <item>
      <title>Registry crossed 8,300 verified nodes across 37 sovereign pillars</title>
      <link>https://bidda.com/changelog#20260528</link>
      <guid isPermaLink="true">https://bidda.com/changelog#20260528</guid>
      <description>Bidda now spans 9,964 source-verified compliance nodes across 39 sovereign pillars, with zero critical schema violations. New depth this cycle: US federal statutory framework (RICO, mail and wire fraud, Hobbs Act, FISA, SECURE Act, SECURE 2.0, REAL ID, EU-US Data Privacy Framework), UK financial and human-rights law (Banking Act 2009, Human Rights Act 1998, Subsidy Control Act 2022), Australia federal criminal and digital-health law (Crimes Act 1914, My Health Records Act 2012), and the three Sprint J RegTech pillars: Data Protection &amp; Privacy, Trade Compliance &amp; Export Controls, and Financial Crime, AML &amp; Sanctions.</description>
      <pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Engineering</dc:creator>
      <category>Changelog · Registry</category>
    </item>
    <item>
      <title>MITRE ATT&amp;CK Enterprise, Explained for Compliance Teams</title>
      <link>https://bidda.com/insights/mitre-attack-enterprise-explained</link>
      <guid isPermaLink="true">https://bidda.com/insights/mitre-attack-enterprise-explained</guid>
      <description>MITRE ATT&amp;CK Enterprise is the most widely adopted knowledge base of real-world adversary behaviour, organising how attackers operate into 14 tactics and hundreds of techniques. Bidda turns each technique into a source-verified node and crosswalks it to the control frameworks auditors actually test against, so a security or compliance team can move from threat to obligation in one query.</description>
      <pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Sovereignty Engineering Group</dc:creator>
      <category>Insights · MITRE Frameworks</category>
    </item>
    <item>
      <title>MITRE ATT&amp;CK for Mobile: Threats to iOS and Android Fleets</title>
      <link>https://bidda.com/insights/mitre-attack-mobile-explained</link>
      <guid isPermaLink="true">https://bidda.com/insights/mitre-attack-mobile-explained</guid>
      <description>MITRE ATT&amp;CK for Mobile documents how adversaries compromise iOS and Android devices, from drive-by compromise to input capture and location tracking. As corporate data moves onto phones and tablets, Bidda maps each mobile technique to the mobile-management and secure-development controls that contain it, including NIST SP 800-124 and OWASP MASVS.</description>
      <pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Sovereignty Engineering Group</dc:creator>
      <category>Insights · MITRE Frameworks</category>
    </item>
    <item>
      <title>MITRE ATT&amp;CK for ICS: Defending Operational Technology</title>
      <link>https://bidda.com/insights/mitre-attack-ics-explained</link>
      <guid isPermaLink="true">https://bidda.com/insights/mitre-attack-ics-explained</guid>
      <description>MITRE ATT&amp;CK for ICS describes how adversaries attack the industrial control systems that run power grids, water treatment, manufacturing, and other physical processes. Because an ICS attack can cause physical harm, not just data loss, Bidda maps each ICS technique to the operational-technology standards that govern critical infrastructure, including IEC 62443, NIST SP 800-82, and NERC CIP.</description>
      <pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Sovereignty Engineering Group</dc:creator>
      <category>Insights · MITRE Frameworks</category>
    </item>
    <item>
      <title>MITRE ATLAS: The Threat Matrix for AI and Machine Learning Systems</title>
      <link>https://bidda.com/insights/mitre-atlas-explained</link>
      <guid isPermaLink="true">https://bidda.com/insights/mitre-atlas-explained</guid>
      <description>MITRE ATLAS is the adversary knowledge base for AI and machine learning systems, modelled on ATT&amp;CK and informed by real attacks and published research. It documents how attackers poison training data, evade and steal models, and jailbreak large language models. Bidda maps each ATLAS technique to the AI governance obligations that now carry legal weight, including the EU AI Act and the NIST AI Risk Management Framework.</description>
      <pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Sovereignty Engineering Group</dc:creator>
      <category>Insights · MITRE Frameworks</category>
    </item>
    <item>
      <title>MITRE D3FEND: A Knowledge Graph of Cyber Countermeasures</title>
      <link>https://bidda.com/insights/mitre-d3fend-explained</link>
      <guid isPermaLink="true">https://bidda.com/insights/mitre-d3fend-explained</guid>
      <description>MITRE D3FEND is a knowledge graph of cybersecurity countermeasures developed by MITRE with funding from the National Security Agency. Where ATT&amp;CK catalogues offence, D3FEND catalogues defence, and it links the two through the digital artifacts an attack touches. Bidda maps D3FEND techniques to NIST 800-53 and the CIS Controls so defenders can move from a defensive capability to its compliance evidence.</description>
      <pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Sovereignty Engineering Group</dc:creator>
      <category>Insights · MITRE Frameworks</category>
    </item>
    <item>
      <title>MITRE CAPEC: A Dictionary of Attack Patterns</title>
      <link>https://bidda.com/insights/mitre-capec-explained</link>
      <guid isPermaLink="true">https://bidda.com/insights/mitre-capec-explained</guid>
      <description>MITRE CAPEC is a public catalogue of common attack patterns, the repeatable methods adversaries use to exploit weaknesses in software and systems. Tightly linked to the Common Weakness Enumeration, CAPEC is a cornerstone of threat modelling and secure development. Bidda maps each attack pattern to the secure-coding and verification standards that prevent it, including OWASP ASVS and the NIST Secure Software Development Framework.</description>
      <pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Sovereignty Engineering Group</dc:creator>
      <category>Insights · MITRE Frameworks</category>
    </item>
    <item>
      <title>Every key page now has a JS-free plain-text mirror, and refresh stays put</title>
      <link>https://bidda.com/changelog#20260525</link>
      <guid isPermaLink="true">https://bidda.com/changelog#20260525</guid>
      <description>Developer docs, methodology, use cases, pricing, about, audit trail, and node verification each ship a plain-text mirror so AI assistants and search engines that do not run JavaScript can read the full page, including the developer code examples. The sitemap and AI discovery manifests were expanded to list every public page. Refreshing any deep page now keeps you on that page instead of returning to the homepage.</description>
      <pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Engineering</dc:creator>
      <category>Changelog · Discoverability</category>
    </item>
    <item>
      <title>New briefings on every MITRE framework Bidda maps</title>
      <link>https://bidda.com/changelog#20260525</link>
      <guid isPermaLink="true">https://bidda.com/changelog#20260525</guid>
      <description>Sovereign Insights now carries a dedicated briefing for each MITRE framework in the registry: ATT&amp;CK Enterprise, ATT&amp;CK Mobile, ATT&amp;CK ICS, ATLAS, D3FEND, and CAPEC. Each explains what the framework covers, how Bidda crosswalks it to NIST 800-53, ISO 27001, PCI DSS and other standards, and how to query it through the API and MCP server.</description>
      <pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Engineering</dc:creator>
      <category>Changelog · Insights</category>
    </item>
    <item>
      <title>Registry passed 7,000 verified nodes</title>
      <link>https://bidda.com/changelog#20260524</link>
      <guid isPermaLink="true">https://bidda.com/changelog#20260524</guid>
      <description>Bidda now spans 9,964 source-verified compliance nodes across 39 sovereign pillars, with zero critical schema violations. Recent depth came from expanded United States federal regulation (eCFR) and sanctions (OFAC) coverage.</description>
      <pubDate>Sun, 24 May 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Engineering</dc:creator>
      <category>Changelog · Registry</category>
    </item>
    <item>
      <title>Self-serve account dashboard, key rotation, and recovery</title>
      <link>https://bidda.com/changelog#20260517</link>
      <guid isPermaLink="true">https://bidda.com/changelog#20260517</guid>
      <description>A new account area lets API customers view their plan, rotate their API key, and review a per-request audit log of their own usage. Lost access can be restored through magic-link recovery, with no passwords to store or leak.</description>
      <pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Engineering</dc:creator>
      <category>Changelog · Platform</category>
    </item>
    <item>
      <title>Plain-text MITRE mirrors, security.txt updated, /status /aup /security pages live</title>
      <link>https://bidda.com/changelog#20260513</link>
      <guid isPermaLink="true">https://bidda.com/changelog#20260513</guid>
      <description>Added /mitre.txt, /mitre-attack.txt, /atlas.txt, /d3fend.txt, /capec.txt as fully crawlable plain-text mirrors of the matrix pages for AI tools that do not execute JavaScript. RFC 9116 /.well-known/security.txt refreshed with security@bidda.com contact and safe-harbor terms. New /status page reads live from /api/v1/registry-health.json. New /aup acceptable use policy and /security vulnerability disclosure page. Privacy policy now lists all named sub-processors per GDPR Article 28 (see /privacy section 08 for the current list).</description>
      <pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Engineering</dc:creator>
      <category>Changelog · Trust</category>
    </item>
    <item>
      <title>All 34 sovereign pillars now visible from the homepage hero</title>
      <link>https://bidda.com/changelog#20260512</link>
      <guid isPermaLink="true">https://bidda.com/changelog#20260512</guid>
      <description>The full set of 34 industries Bidda covers is reachable within one scroll of the homepage, including the three newest pillars: immigration, agriculture, and water. A site-wide copy and typography pass brought consistency to every public page.</description>
      <pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Engineering</dc:creator>
      <category>Changelog · Platform</category>
    </item>
    <item>
      <title>ATT&amp;CK and D3FEND views rebuilt to the canonical MITRE Navigator layout</title>
      <link>https://bidda.com/changelog#20260512</link>
      <guid isPermaLink="true">https://bidda.com/changelog#20260512</guid>
      <description>The /mitre-attack and /d3fend matrices now use the same horizontal-scroll Navigator pattern as /atlas: one column per tactic, technique cards stacked under each header, click to open a detail panel with the BLUF, the linked node_id, the external attack.mitre.org / d3fend.mitre.org URL, and an Open Node button. D3FEND also shows &quot;Counters ATT&amp;CK&quot; with a cross-matrix link.</description>
      <pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Engineering</dc:creator>
      <category>Changelog · MITRE</category>
    </item>
    <item>
      <title>Institutional trust signals added to About + legal trio</title>
      <link>https://bidda.com/changelog#20260512</link>
      <guid isPermaLink="true">https://bidda.com/changelog#20260512</guid>
      <description>New &quot;Who Builds Bidda&quot; section on /about with CIPC registration number 2026/363776/07, Cape Town registered office, integrity endpoint, and the public legal trio. Privacy, Disclaimer, Terms, and Refund Policy footers now carry the CIPC number and Cape Town office. Nav: &quot;ATLAS&quot; link replaced with &quot;MITRE&quot; pointing at the hub.</description>
      <pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Engineering</dc:creator>
      <category>Changelog · Trust</category>
    </item>
    <item>
      <title>Registry crossed 5,419 nodes across 34 sovereign pillars</title>
      <link>https://bidda.com/changelog#20260511</link>
      <guid isPermaLink="true">https://bidda.com/changelog#20260511</guid>
      <description>Latest CAPEC and D3FEND density batches landed. 9,964 verified compliance nodes are now live across 39 industries, including a MITRE layer across 6 frameworks (ATT&amp;CK Enterprise/Mobile/ICS, ATLAS, D3FEND, CAPEC). Zero critical schema violations.</description>
      <pubDate>Mon, 11 May 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Engineering</dc:creator>
      <category>Changelog · Registry</category>
    </item>
    <item>
      <title>CAPEC added as the 6th MITRE framework in the Rosetta Stone</title>
      <link>https://bidda.com/changelog#20260511</link>
      <guid isPermaLink="true">https://bidda.com/changelog#20260511</guid>
      <description>CAPEC (Common Attack Pattern Enumeration and Classification) joined ATT&amp;CK Enterprise, ATT&amp;CK Mobile, ATT&amp;CK ICS, ATLAS, and D3FEND. The MCP get_mitre_mapping tool now recognises CAPEC-NN technique IDs and returns the cross-framework mapping. Reverse mappings into OWASP ASVS, NIST 800-53, ISO 27001, PCI DSS applied.</description>
      <pubDate>Mon, 11 May 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Engineering</dc:creator>
      <category>Changelog · MITRE</category>
    </item>
    <item>
      <title>MCP server and /scan endpoint live</title>
      <link>https://bidda.com/changelog#20260511</link>
      <guid isPermaLink="true">https://bidda.com/changelog#20260511</guid>
      <description>Bidda is reachable from any MCP client (Claude Desktop, Cursor, Windsurf, claude.ai connectors) at https://bidda.com/mcp with 9 tools across discovery and runtime intelligence. The /scan REST endpoint accepts source code or a git diff and returns ranked regulatory matches plus a risk level. Free for discovery, $0.01 USDC for full vault unlocks.</description>
      <pubDate>Mon, 11 May 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Engineering</dc:creator>
      <category>Changelog · Platform</category>
    </item>
    <item>
      <title>Free sample node published: EU AI Act Article 10</title>
      <link>https://bidda.com/changelog#20260504</link>
      <guid isPermaLink="true">https://bidda.com/changelog#20260504</guid>
      <description>EU AI Act Article 10 (Data Governance for High-Risk AI Systems) is publicly accessible without payment so prospective buyers can see exactly what a full 13-key vault node contains. Deterministic workflow, actionable schema, 7 primary legal citations, framework crosswalks.</description>
      <pubDate>Mon, 04 May 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Engineering</dc:creator>
      <category>Changelog · Registry</category>
    </item>
    <item>
      <title>GDPR Compliance Checklist 2026: The Complete Guide for AI and Data Systems</title>
      <link>https://bidda.com/insights/gdpr-compliance-checklist-2026</link>
      <guid isPermaLink="true">https://bidda.com/insights/gdpr-compliance-checklist-2026</guid>
      <description>GDPR compliance in 2026 is no longer just about cookie banners. AI-driven data processing, automated profiling, and cross-border data flows have introduced obligations that most compliance programmes have not fully addressed. This guide maps the 12 most critical GDPR requirements - including Article 22 automated decision-making restrictions and the 2021 Standard Contractual Clauses - to specific, verifiable compliance actions.</description>
      <pubDate>Thu, 30 Apr 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Sovereignty Engineering Group</dc:creator>
      <category>Insights · Compliance &amp; Law</category>
    </item>
    <item>
      <title>NIST AI Risk Management Framework in 2026: From Checklist to Executable Compliance</title>
      <link>https://bidda.com/insights/nist-ai-risk-management-framework-2026</link>
      <guid isPermaLink="true">https://bidda.com/insights/nist-ai-risk-management-framework-2026</guid>
      <description>The NIST AI Risk Management Framework (AI RMF 1.0) is the closest thing the United States has to a mandatory AI governance standard - and its search volume is up 70% in 2026 as organisations race to demonstrate compliance. This guide breaks down the four core functions (GOVERN, MAP, MEASURE, MANAGE) with specific implementation requirements, and explains how the Generative AI Profile (NIST AI 600-1) extends the framework for LLMs and agentic systems.</description>
      <pubDate>Thu, 30 Apr 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Sovereignty Engineering Group</dc:creator>
      <category>Insights · AI Architecture</category>
    </item>
    <item>
      <title>EU AI Act 2026: What High-Risk AI Systems Must Do Now</title>
      <link>https://bidda.com/insights/eu-ai-act-high-risk-compliance-2026</link>
      <guid isPermaLink="true">https://bidda.com/insights/eu-ai-act-high-risk-compliance-2026</guid>
      <description>The EU AI Act became fully enforceable for high-risk AI systems in August 2026. Organisations deploying AI in Annex III use cases - biometric identification, critical infrastructure, education, employment, essential services, law enforcement, migration, and justice - now face mandatory technical documentation, conformity assessments, and ongoing monitoring obligations. This is the most consequential AI regulation in force globally. This guide explains exactly what is required.</description>
      <pubDate>Thu, 30 Apr 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Sovereignty Engineering Group</dc:creator>
      <category>Insights · Compliance &amp; Law</category>
    </item>
    <item>
      <title>AI Governance Certification in 2026: AIGP, ISO 42001, and What Actually Qualifies You</title>
      <link>https://bidda.com/insights/ai-governance-certification-guide-2026</link>
      <guid isPermaLink="true">https://bidda.com/insights/ai-governance-certification-guide-2026</guid>
      <description>AI governance certification searches are up 20% in 2026 as compliance officers, legal engineers, and AI practitioners race to demonstrate qualified governance capability. The market has converged on three primary credentials: the IAPP AI Governance Professional (AIGP), ISO 42001 organisational certification, and the emerging EU AI Act Compliance Specialist designation. This guide explains what each covers, what it misses, and which one you need for your role.</description>
      <pubDate>Thu, 30 Apr 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Sovereignty Engineering Group</dc:creator>
      <category>Insights · AI Architecture</category>
    </item>
    <item>
      <title>AI Compliance in Healthcare 2026: What HIPAA, FDA, and the EU AI Act Actually Require</title>
      <link>https://bidda.com/insights/ai-compliance-healthcare-2026</link>
      <guid isPermaLink="true">https://bidda.com/insights/ai-compliance-healthcare-2026</guid>
      <description>Healthcare is the highest-risk sector for AI compliance failures - and the most heavily regulated. AI systems in clinical settings now operate under three overlapping frameworks simultaneously: HIPAA (US data privacy), FDA AI/ML-based Software as a Medical Device (SaMD) regulations, and the EU AI Act&apos;s Annex III high-risk classification for medical device AI. Getting this right requires knowing where each framework starts, stops, and overlaps.</description>
      <pubDate>Thu, 30 Apr 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Sovereignty Engineering Group</dc:creator>
      <category>Insights · Compliance &amp; Law</category>
    </item>
    <item>
      <title>Registry certified fully source-traceable and audit-ready</title>
      <link>https://bidda.com/changelog#20260430</link>
      <guid isPermaLink="true">https://bidda.com/changelog#20260430</guid>
      <description>Every workflow step in every node now traces directly to its primary source instrument. No placeholder or unverified content reaches customers: each step is grounded in the cited regulation, standard, or framework.</description>
      <pubDate>Thu, 30 Apr 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Engineering</dc:creator>
      <category>Changelog · Quality</category>
    </item>
    <item>
      <title>Weekly Source Integrity Watcher live (Phase 4b.1)</title>
      <link>https://bidda.com/changelog#20260429</link>
      <guid isPermaLink="true">https://bidda.com/changelog#20260429</guid>
      <description>Every primary source URL in the registry is now fingerprinted weekly by TLS SPKI hash and content SHA-256. Tamper-evident git Merkle chain. Public health endpoint at /api/v1/registry-health.json with no authentication required.</description>
      <pubDate>Wed, 29 Apr 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Engineering</dc:creator>
      <category>Changelog · Trust</category>
    </item>
    <item>
      <title>Skyfire and the Agentic Economy: How AI Agents Pay for What They Know</title>
      <link>https://bidda.com/insights/skyfire-agentic-economy-bidda</link>
      <guid isPermaLink="true">https://bidda.com/insights/skyfire-agentic-economy-bidda</guid>
      <description>The agentic economy is built on a simple premise: AI agents need to transact, not just compute. Skyfire provides the payment rails. Bidda provides the verified intelligence. Together, they enable the first generation of AI systems that can autonomously acquire, verify, and act on compliance-grade regulatory knowledge - without a human in the loop.</description>
      <pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Sovereignty Engineering Group</dc:creator>
      <category>Insights · Agent Economy</category>
    </item>
    <item>
      <title>ESG Reporting in the Age of Autonomous Agents</title>
      <link>https://bidda.com/insights/esg-autonomous-compliance</link>
      <guid isPermaLink="true">https://bidda.com/insights/esg-autonomous-compliance</guid>
      <description>Environmental, Social, and Governance reporting is rapidly becoming a legal obligation across major jurisdictions. Autonomous agents managing ESG disclosures need verified, authority-backed intelligence to avoid both regulatory penalties and reputational greenwashing exposure.</description>
      <pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Sovereignty Engineering Group</dc:creator>
      <category>Insights · ESG &amp; Sustainability</category>
    </item>
    <item>
      <title>Deploying AI Agents in Healthcare: The Compliance Framework</title>
      <link>https://bidda.com/insights/healthcare-agent-compliance</link>
      <guid isPermaLink="true">https://bidda.com/insights/healthcare-agent-compliance</guid>
      <description>Healthcare is the highest-stakes environment for autonomous AI deployment. HIPAA data handling rules, HL7 FHIR interoperability standards, and the FDA&apos;s Software as a Medical Device (SaMD) framework must all be satisfied before an agent can legally operate in a clinical pathway.</description>
      <pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Sovereignty Engineering Group</dc:creator>
      <category>Insights · Medical &amp; Healthcare</category>
    </item>
    <item>
      <title>Hardening Autonomous Agents Against Adversarial Attacks</title>
      <link>https://bidda.com/insights/cybersecurity-agent-hardening</link>
      <guid isPermaLink="true">https://bidda.com/insights/cybersecurity-agent-hardening</guid>
      <description>Autonomous agents with tool-use capabilities, network access, and financial settlement authority represent a new class of attack surface. NIST CSF 2.0&apos;s Govern function, the OWASP LLM Top 10, and FIPS 203 post-quantum cryptography standards define the baseline security architecture required for production agentic deployments.</description>
      <pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Sovereignty Engineering Group</dc:creator>
      <category>Insights · Cybersecurity</category>
    </item>
    <item>
      <title>Enterprise AI Governance: From Policy to Deployed Agent</title>
      <link>https://bidda.com/insights/enterprise-ai-governance-onboarding</link>
      <guid isPermaLink="true">https://bidda.com/insights/enterprise-ai-governance-onboarding</guid>
      <description>Enterprise AI governance is no longer a theoretical exercise. Boards, regulators, and insurers are demanding documented, auditable evidence that AI systems are operating within defined legal and ethical boundaries. This guide outlines the governance programme components that use Sovereign Intelligence as the compliance foundation.</description>
      <pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Sovereignty Engineering Group</dc:creator>
      <category>Insights · Enterprise Guide</category>
    </item>
    <item>
      <title>Defining Sovereign Knowledge Nodes: The Architecture of Trust</title>
      <link>https://bidda.com/insights/defining-sovereign-knowledge-nodes</link>
      <guid isPermaLink="true">https://bidda.com/insights/defining-sovereign-knowledge-nodes</guid>
      <description>Sovereign Knowledge Nodes represent the evolution of AI memory, moving beyond traditional RAG systems to create cryptographically signed, standard-aligned, and executable intelligence assets that autonomous agents can settle via L402 protocols.</description>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Sovereignty Engineering Group</dc:creator>
      <category>Insights · AI Architecture</category>
    </item>
    <item>
      <title>From NIST, ISO &amp; EU AI Act to Executable Workflows</title>
      <link>https://bidda.com/insights/nist-iso-eu-ai-act-workflows</link>
      <guid isPermaLink="true">https://bidda.com/insights/nist-iso-eu-ai-act-workflows</guid>
      <description>Integrating global standards like ISO 42001 and the EU AI Act into autonomous systems requires moving beyond static PDF documentation to executable knowledge nodes that define strict, auditable boundaries for agentic behavior.</description>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Sovereignty Engineering Group</dc:creator>
      <category>Insights · Compliance &amp; Law</category>
    </item>
    <item>
      <title>The Micro-Economy of Truth: Why Pay-Per-Intelligence Wins</title>
      <link>https://bidda.com/insights/micro-economy-of-truth-l402</link>
      <guid isPermaLink="true">https://bidda.com/insights/micro-economy-of-truth-l402</guid>
      <description>The future of the AI economy relies on micropayments for ultra-high-fidelity data. Using the L402 protocol and compatible Web3 payment infrastructure, Bidda allows agents to purchase precise droplets of intelligence exactly when they are needed - with no subscriptions, no data collection, and no friction.</description>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Sovereignty Engineering Group</dc:creator>
      <category>Insights · Agent Economy</category>
    </item>
    <item>
      <title>Integrating Sovereign Knowledge: A Technical Blueprint</title>
      <link>https://bidda.com/insights/integrating-sovereign-knowledge-guide</link>
      <guid isPermaLink="true">https://bidda.com/insights/integrating-sovereign-knowledge-guide</guid>
      <description>Developers can rapidly integrate Sovereign Nodes into their agentic workflows using our L402-enabled REST API. This guide outlines the core architectural patterns for discovery, payment settlement, and verified intelligence ingestion.</description>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
      <dc:creator>Bidda Sovereignty Engineering Group</dc:creator>
      <category>Insights · Developer Guide</category>
    </item>
  </channel>
</rss>
