Trust
Where your governance record lives, and who can reach it.
Your AI systems, policies and evidence are yours. This page sets out how we hold them.
Your content and our content
The platform keeps two kinds of content separate.
Platform content
We maintain this
- Regulation text and articles
- Policy templates
- Control definitions
- Risk taxonomy
- Use case library
- AI tool catalogue
kept separate
Your content
You own this
- Your AI systems
- Your policies
- Your compliance gaps
- Your evidence
- Your audit trail
Never touched by updates.
Who can see what
Access is controlled by role. Members are invited, given a role, can have access revoked, and every access change is logged. Submitters cannot approve their own work.
The audit trail
Activity is append-only. Each entry records who acted, what changed, the affected record, whether it was allowed or blocked, and the reason where one applies.
How updates reach you
Signed, versioned content bundles.
Signing allows a bundle to be verified. Importing the same bundle twice has no effect, so repeated imports cannot duplicate or damage content.
Hosting, regions and deployment options: details to be supplied.
Encryption, backups, retention and account closure: details to be supplied.
Security contact and response time: details to be supplied.
Sub-processors: details to be supplied.
