Authoritative record
The compliance record is stored in the selected EEA infrastructure. Approved subprocessors may process only the information needed for their contracted function.
The authoritative case record, access model, AI processing and subprocessor relationships are documented for security, privacy, legal and procurement review.
This public summary is intentionally high level. Detailed architecture, named provider information and control evidence are supplied during qualified procurement review.
The compliance record is stored in the selected EEA infrastructure. Approved subprocessors may process only the information needed for their contracted function.
Firm data is segregated using database level controls so users from one firm cannot access another firm’s records.
Analysts, managers, MLROs, administrators and read only reviewers receive access according to their function.
Data is encrypted in transit and at rest using the controls provided by the managed hosting environment.
Commercial AI services operate under contractual data protections. Client data is not used to train public models.
Model output does not approve a customer, submit a filing or send a material client communication without authorised human action.
File access, uploads, screening, review generation, assignments, notes, decisions and sign offs can be recorded against the case.
Retention can be configured to the firm’s requirements, with export, termination and deletion handled under the DPA.
Material incidents are triaged, contained and communicated to affected firms in line with contractual and data protection obligations.
Confidential detail is provided to qualified prospective clients under the appropriate commercial and data protection process.
Platform overview, data flow, access model, encryption, AI use, subprocessors, retention and incident response.
Controller and processor roles, processing instructions, security measures, subprocessor terms and transfer safeguards.
Provider, purpose, location, assurance and relevant contractual safeguards.
Model use, training restrictions, data minimisation, retention configuration and human control boundaries.
A fictional complete case showing the evidence, findings, challenge and human decision record.
Configuration evidence, test materials and available assurance supplied according to the stage of procurement.
The authoritative compliance record is stored in EEA infrastructure. Approved subprocessors may process limited data outside the EEA under applicable contractual safeguards.
This distinction is important. Storage location and processing are not the same thing, and firms should assess both when reviewing data residency. We state the position precisely rather than claiming that no data ever leaves the EEA.
We can provide the procurement pack, DPA and controlled technical detail alongside the product evaluation.