The compliance posture is baked into the shape of the install itself: how data is scoped, where models run, and what we refuse to build.
Your data stays in your estate, with residency-safe routing available and an audit trail on every action the system takes.
Contracts drawn the way the processing actually works: Article 28 DPA with a joint-controller annex, drawn the way the processing genuinely works.
Each install is its own estate. Nothing you teach your system trains anyone else's, and no client data crosses installs.
For residency-sensitive clients, model traffic routes through AWS Bedrock eu-west-2 or GCP Vertex AI EU.
Recruitment screening, credit decisioning and the other EU AI Act Annex III categories are out of scope by design.
The full legal surface lives on its own pages: privacy policy, cookies, residency options, DPA and joint-controller annex.