Live Compliance Scorecard

AM8 Trust & Compliance

AM8 runs the same audit it sells, on itself, continuously, and hands the results to any customer or auditor who asks. Every figure below is produced by our own platform. Where something is not yet measured, this page says so rather than showing a green result.

Served 2026-08-25 · Platform v4.0

Frameworks & Compliance Posture

The frameworks AM8 builds and measures itself against. AM8 holds no third-party certifications yet and does not claim any. Everything below is posture we can show, not a badge we bought.

GDPR

EU data protection: how we process data

EU AI Act

Regulation 2024/1689: self-assessed and live-monitored

ISO/IEC 42001

Vocabulary used in generated documentation. Not adopted, not certified, and no ISO control is run against AM8 itself.

Jurisdiction Coverage

A jurisdiction is LIVE only when the full compliance loop closes on its real rule pack in our gate test: classification, document generation, an independent cross-check by a second system, human sign-off, and a cryptographically signed, integrity-verified audit dossier. Earned, never declared.

LIVE

European Union

EU AI Act (post-Omnibus dates) · GDPR touchpoints

Gate passed 12 Aug 2026

LIVE

United Arab Emirates

PDPL · DIFC Regulation 10 · UAE AI Charter

Gate passed 12 Aug 2026

United Kingdom

Pro-innovation framework · ICO guidance

Planned

Saudi Arabia

SDAIA · Saudi PDPL

Planned

Qatar

PDPPL (Law 13/2016) · QFC data protection · National AI Strategy

Planned

Singapore

PDPC · IMDA model governance

Planned

US states

Colorado-class state AI acts

Planned

South Korea

AI Framework Act (Jan 2026)

Planned

Japan

AI promotion regime · APPI

Planned

What “LIVE” means here: The full loop ran on the real rule pack: the system was classified and the ruling confirmed by a named expert, the documents were generated, their claims were independently cross-checked by a second system, a named human signed off on the exact content approved, and the resulting audit dossier was cryptographically signed and integrity-verified. First clean pass: 12 August 2026. Full gate record available under NDA.

EU AI Act Score

Article 9, 13, 17, 26, 43
88/100
Below 90 publish threshold

Scored 4 July 2026

Cookie Compliance

GDPR Art. 7 + ePrivacy
Consent mechanismFirst-party consent banner (no third-party consent-management platform).
Third-party scriptsOne: Vercel Web Analytics, loaded only if you consent to analytics. It is cookieless, served from this domain rather than a tracker origin, and never loaded at all if you refuse. No advertising, marketing or session-replay scripts of any kind.
Consent decisions recordedYes, every decision is logged with its evidence

AM8 does not yet run an automated cookie scan of its own site. This section reports what is measured, not a scan result.

Continuous Control Monitoring

Last measured 24 Aug 2026

AM8 runs the same continuous control monitoring it sells, against its own AI systems. Every applicable control is re-tested on a schedule by the live engine rather than reviewed by hand once a year.

Controls monitored

11

Frameworks

EU AI Act · GDPR · UAE (PDPL / DIFC / AI Charter)

Control-by-control results, including any failing controls and the open remediation against them, are shared with customers, prospects and auditors on request under NDA. security@am8-ai-governance.tech

Evidence Integrity

Verifiable without AM8

Every evidence pack AM8 exports is signed with this key. Anyone holding a pack can confirm, offline and without contacting AM8, that it is the pack we produced and that not one record in it has changed since. Compare the key id here against the one inside the pack. A signature proves the pack is unaltered and who signed it; it does not make its contents true, and we do not claim otherwise.

Applies to packs exported from August 2026 onward. Earlier exports carry a content hash only and are not independently verifiable, and they are not claimed to be.

To check a pack, compare this key against the one inside it, then run the verifier.

Signature
Ed25519
Key ID
9d3787bd05c60bea29772f1ccd90fef6
Public key (spki-der-base64)
MCowBQYDK2VwAyEANNpyl8wJbIrEQeyV7eyS0J7hGNARvvZTYAXJSWSF10E=
Verifier
https://app.am8-ai-governance.tech/verify-audit-pack.mjs (runs offline, no dependencies)

Sub-Processor DPAs

GDPR Art. 28 · live from our register

Per-sub-processor GDPR Art. 28 status, straight from our register, including any agreement still pending execution. No customer tenant is onboarded onto a sub-processor whose agreement is not yet in force.

ProviderPurposeData regionDPA status
Mistral AIIndependent cross-check of AI-generated compliance documents (checks only: flags discrepancies for human review, never edits)EU (France, EU-resident inference) Signed
AnthropicAI processing (Claude API)US Signed
SupabaseDatabase, auth & storageEU (Frankfurt) Signed
VercelFrontend hosting, CDN & cookieless page analyticsEU / US Signed
ResendTransactional email deliveryUS Signed
StripePayment processing & billingEU / US Signed
SentryError monitoring (PII-scrubbed)US Signed
RailwayBackend hosting (API & workers)EU (Amsterdam) Pending

Security Controls

Data residency

Customer data is stored and processed in the EU (Supabase, Frankfurt). AI model inference is processed by Anthropic via its global (US) API under Standard Contractual Clauses; the vendor does not train on API data; the provider does not currently offer an EU-region option for this model tier; every inference call logs its endpoint.

Encryption at rest

AES-256 (Supabase managed)

Encryption in transit

TLS 1.3 enforced

Authentication

Token-based authentication with per-customer access control enforced on every record

Backups

7-day Point-in-Time Recovery (Supabase Pro)

Audit logging

Tamper-evident records of every sensitive action, every control test and every piece of collected evidence. Corrections supersede; history is never rewritten

PII scrubbing

Sentry configured to strip all personal data fields

Access control

Role-based (Owner / Admin / Member) with RBAC

Webhook verification

Stripe webhook signatures verified on every request

AI System Transparency

EU AI Act Article 13 + Article 50 disclosure

Claude (Anthropic)

Model: claude-sonnet-5

limited risk

Used for

  • Compliance document generation (asynchronous, queued for processing)
  • EU AI Act Article 5 prohibited practice screening
  • Weekly and monthly executive report generation
  • UAE Charter alignment assessment generation

Safeguards

  • All AI-generated compliance documents carry a DRAFT watermark until reviewed by a qualified human
  • No AI output is submitted to regulators without human sign-off
  • AI responses are schema-validated before storage, and malformed output is rejected
  • Max token limits enforced per document type to prevent runaway generation
  • Every generated document is checked for unresolved placeholders and for citations that do not match the law it cites; where a second, independent system is configured, it re-derives the claims in that document and flags any discrepancy for the reviewer. A document that was not cross-checked is labelled as such, never presented as verified
Article 50 disclosure: Content generated by Claude (Anthropic) is AI-assisted. All AI-generated compliance documents are clearly marked as DRAFT until reviewed by a qualified compliance professional. AM8 does not present AI output as certified legal advice.

Establishment & Supervisory Authority

GDPR Article 3 · EU-established

AM8 SASU is established in France, within the EU. As an EU-established controller, AM8 is not required to appoint an Article 27 EU representative. EU data subjects may lodge a complaint with their local supervisory authority or with the French CNIL.

Data protection: privacy@am8-ai-governance.tech

Lead authority: CNIL (Commission Nationale de l'Informatique et des Libertés) · cnil.fr

UK Data Subjects

UK GDPR

If you are in the United Kingdom, you may lodge a complaint with the UK Information Commissioner's Office (ICO). Where AM8 is required to appoint a UK Article 27 representative, those details will be published here.

Contact: privacy@am8-ai-governance.tech

ICO · ico.org.uk

Documents & Security Contact

Report a vulnerability: we welcome responsible disclosure. Email our security team at security@am8-ai-governance.tech and we will acknowledge your report within two business days.

For data protection enquiries contact privacy@am8-ai-governance.tech. AM8 is a product of AM8 SASU, registered in France.