The problem
From 2 August 2026, compliance with the EU AI Act will become mandatory. GDPR enforcement by national supervisory authorities is increasing. Platforms built on US hyperscalers (AWS, Azure, GCP) are at risk under the CLOUD Act. Retrofitting compliance is costly and fragile.
Our approach
- 100% EU-hosted: 8 providers, 5 EU countries, no CLOUD Act risk
- GDPR: 72-hour deletion, 24-hour data export, 30-day audit trail
- EU AI Act: transparency and disclosure, human oversight, provenance tracking
- PCI DSS SAQ-A compliant via Adyen (sessions flow)
- 0 npm audit vulnerabilities, security headers on 5 domains
Platform burden of proof
- 7 GDPR rights implemented, 11-section privacy policy
- EU AI Act risk classification: low
- Provenance SHA-256 signature on all AI-generated content
- WCAG 2.1 AA: aria-labels, keyboard navigation, contrast ≥4.5:1
KPIs: what you measure
Compliance audit score (%)
GDPR request processing time
Security vulnerabilities (0 = target)
AI transparency coverage (%)
Related modules
Would you like to see how Compliance & Trust works for your organisation?
Schedule a strategic meeting