Compliance by design

Built for your most sensitive data — compliant across every layer

For AI that operates across the organization, compliance and information security are part of the product, not later documentation. One shared, compliance-ready foundation, with stricter controls activated by customer, data, and intended use.

Regulatory frameworks

Designed against the EU regulatory landscape

The foundation is built to the frameworks that govern AI, data, and resilience in the European Union.

The five pillars

What compliance looks like across every layer

Each pillar is part of the product surface — not later documentation. Below is what each one covers in practice.

GDPR & data governance

Clear controller/processor roles, lawful-basis mapping, and full data-subject rights.

  • Compliant DPA with controller/processor roles
  • Data inventory, purpose limitation, and minimisation
  • Explicit retention for chats, files, memory, and outputs
  • Export, correction, and deletion of personal data
  • Tenant isolation and least-privilege access
  • Tested 72-hour incident-notification process

EU AI Act governance

Every AI capability records purpose, provider, data, evidence, owner, and approval.

  • AI interaction and AI-assisted outputs clearly identified
  • Recommendations kept distinct from verified facts
  • AI cannot approve its own work
  • Human approval required for consequential actions
  • Stop, override, and correction supported
  • Each domain classified before activation; prohibited uses blocked

Executive & financial controls

Deterministic math, canonical values, and immutable, reproducible decisions.

  • Financial calculations use deterministic functions, not model guesses
  • Forecasts, assumptions, and data-as-of dates are visible
  • Narrative, tables, and charts use identical canonical values
  • Read-only integration access by default
  • External writes require explicit approval; maker–checker where needed
  • Approved reports and decisions are immutable and reproducible

Cybersecurity & resilience

A NIS2-aligned baseline with a financial-services overlay for DORA scope.

  • Strong authentication, role-based access, full tenant separation
  • Encryption in transit and at rest; secure secrets
  • Dependency and vulnerability management
  • Audit logs protected from ordinary modification
  • Backup, restore, and disaster-recovery tests
  • Penetration testing and supplier/model-provider risk review

Customer control & portability

You see where data lives, control retention, and can export or exit at any time.

  • See storage location, providers, subprocessors, and integrations
  • Control retention and memory
  • Disable any model, tool, employee, or automation
  • Export files, artifacts, audit history, and metadata
  • Delete the workspace with confirmation
  • Reproduce any approved decision or deliverable — no lock-in
In the product, not a module

Where compliance shows up

  • A Trust & Governance area in administration
  • Inline classification and approval warnings
  • Visible source, data, and AI provenance in outputs
  • An audit and activity view
  • Downloadable compliance evidence for auditors

We build a compliance-ready foundation and require a formal DPO, legal, and security verification before deployment with real executive or customer data. Full compliance depends on the application, deployment, contracts, and each use case being aligned.

Need compliance evidence for a review?

We provide documentation for your DPO, legal, and security teams ahead of any deployment with real executive or customer data.