We help businesses get AI doing real work  ·  Read our letter ↗
trust

Compliance built into how it is put together.

The compliance posture is baked into the shape of the install itself: how data is scoped, where models run, and what we refuse to build.

Your data stays in your estate, with residency-safe routing available and an audit trail on every action the system takes.

UK GDPR
DPA 2018
EU AI ACT

Built into every layer.

Joint-controller contracts

Contracts drawn the way the processing actually works: Article 28 DPA with a joint-controller annex, drawn the way the processing genuinely works.

Sealed installs

Each install is its own estate. Nothing you teach your system trains anyone else's, and no client data crosses installs.

Residency-safe routing

For residency-sensitive clients, model traffic routes through AWS Bedrock eu-west-2 or GCP Vertex AI EU.

High-risk red lines held

Recruitment screening, credit decisioning and the other EU AI Act Annex III categories are out of scope by design.

The register we hold ourselves to.

UK GDPRthe baseline for every install
DPA 2018UK statutory frame, applied by default
DUAA 2025current UK data-use rules, tracked as they land
EU AI ACTposture maintained for EU-facing clients

The full legal surface lives on its own pages: privacy policy, cookies, residency options, DPA and joint-controller annex.

Bring your DPO. We enjoy that conversation.

Talk to us