Compliance Check
This section documents how the platform supports compliance with the regulations and frameworks most relevant to EU customers. It is meant as a starting point for an internal audit, not as legal advice.
Frameworks in scope
| Framework | Why it matters | Platform support |
|---|---|---|
| GDPR | Personal-data handling for EU subjects. | GDPR |
| EU AI Act | Risk classification and obligations for AI systems. | Built-in Compliance Wizard. |
| ISO 27001 | Information security management. | Control mapping. |
| SOC 2 | Service-organisation trust criteria. | Control mapping. |
Pages in this section
- GDPR overview - data subject rights and technical controls.
- EU AI Act - how the in-platform wizard maps to the Act.
- ISO 27001 control mapping - Annex A controls and where they are implemented.
- SOC 2 control mapping - Trust Services Criteria coverage.
- Audit evidence - how to extract evidence for an audit.
Top-line summary
Cross-framework controls
| Item | Status | Notes |
|---|---|---|
| Identity, single sign-on, and role-based access control | Done | - |
| Encryption in transit at the platform perimeter | Done | - |
| Encryption at rest (administrator-configured) | Partial | Available; activation depends on the administrator |
| Per-execution audit trail for every workflow run | Done | - |
| Data stays inside your environment by default | Done | - |
| GDPR data subject rights (access, rectification, erasure) | Partial | Process documented; in-product tooling on roadmap |
| EU AI Act risk classification with auditable PDF | Done | - |
| Versioned workflows with explicit publish step | Done | - |
| Incident response plan and runbook | Administrator-owned; template provided |