AM8 Trust & Compliance
AM8 runs the same audit it sells, on itself, continuously, and hands the results to any customer or auditor who asks. Every figure below is produced by our own platform. Where something is not yet measured, this page says so rather than showing a green result.
Served 2026-08-25 · Platform v4.0
Frameworks & Compliance Posture
The frameworks AM8 builds and measures itself against. AM8 holds no third-party certifications yet and does not claim any. Everything below is posture we can show, not a badge we bought.
GDPR
EU data protection: how we process data
EU AI Act
Regulation 2024/1689: self-assessed and live-monitored
ISO/IEC 42001
Vocabulary used in generated documentation. Not adopted, not certified, and no ISO control is run against AM8 itself.
Jurisdiction Coverage
A jurisdiction is LIVE only when the full compliance loop closes on its real rule pack in our gate test: classification, document generation, an independent cross-check by a second system, human sign-off, and a cryptographically signed, integrity-verified audit dossier. Earned, never declared.
European Union
EU AI Act (post-Omnibus dates) · GDPR touchpoints
Gate passed 12 Aug 2026
United Arab Emirates
PDPL · DIFC Regulation 10 · UAE AI Charter
Gate passed 12 Aug 2026
United Kingdom
Pro-innovation framework · ICO guidance
Planned
Saudi Arabia
SDAIA · Saudi PDPL
Planned
Qatar
PDPPL (Law 13/2016) · QFC data protection · National AI Strategy
Planned
Singapore
PDPC · IMDA model governance
Planned
US states
Colorado-class state AI acts
Planned
South Korea
AI Framework Act (Jan 2026)
Planned
Japan
AI promotion regime · APPI
Planned
What “LIVE” means here: The full loop ran on the real rule pack: the system was classified and the ruling confirmed by a named expert, the documents were generated, their claims were independently cross-checked by a second system, a named human signed off on the exact content approved, and the resulting audit dossier was cryptographically signed and integrity-verified. First clean pass: 12 August 2026. Full gate record available under NDA.
EU AI Act Score
Article 9, 13, 17, 26, 43Scored 4 July 2026
Cookie Compliance
GDPR Art. 7 + ePrivacyAM8 does not yet run an automated cookie scan of its own site. This section reports what is measured, not a scan result.
Continuous Control Monitoring
Last measured 24 Aug 2026AM8 runs the same continuous control monitoring it sells, against its own AI systems. Every applicable control is re-tested on a schedule by the live engine rather than reviewed by hand once a year.
Controls monitored
11
Frameworks
EU AI Act · GDPR · UAE (PDPL / DIFC / AI Charter)
Control-by-control results, including any failing controls and the open remediation against them, are shared with customers, prospects and auditors on request under NDA. security@am8-ai-governance.tech
Evidence Integrity
Verifiable without AM8Every evidence pack AM8 exports is signed with this key. Anyone holding a pack can confirm, offline and without contacting AM8, that it is the pack we produced and that not one record in it has changed since. Compare the key id here against the one inside the pack. A signature proves the pack is unaltered and who signed it; it does not make its contents true, and we do not claim otherwise.
Applies to packs exported from August 2026 onward. Earlier exports carry a content hash only and are not independently verifiable, and they are not claimed to be.
To check a pack, compare this key against the one inside it, then run the verifier.
- Signature
- Ed25519
- Key ID
- 9d3787bd05c60bea29772f1ccd90fef6
- Public key (spki-der-base64)
- MCowBQYDK2VwAyEANNpyl8wJbIrEQeyV7eyS0J7hGNARvvZTYAXJSWSF10E=
- Verifier
- https://app.am8-ai-governance.tech/verify-audit-pack.mjs (runs offline, no dependencies)
Sub-Processor DPAs
GDPR Art. 28 · live from our registerPer-sub-processor GDPR Art. 28 status, straight from our register, including any agreement still pending execution. No customer tenant is onboarded onto a sub-processor whose agreement is not yet in force.
| Provider | Purpose | Data region | DPA status |
|---|---|---|---|
| Mistral AI | Independent cross-check of AI-generated compliance documents (checks only: flags discrepancies for human review, never edits) | EU (France, EU-resident inference) | Signed |
| Anthropic | AI processing (Claude API) | US | Signed |
| Supabase | Database, auth & storage | EU (Frankfurt) | Signed |
| Vercel | Frontend hosting, CDN & cookieless page analytics | EU / US | Signed |
| Resend | Transactional email delivery | US | Signed |
| Stripe | Payment processing & billing | EU / US | Signed |
| Sentry | Error monitoring (PII-scrubbed) | US | Signed |
| Railway | Backend hosting (API & workers) | EU (Amsterdam) | Pending |
Security Controls
Data residency
Customer data is stored and processed in the EU (Supabase, Frankfurt). AI model inference is processed by Anthropic via its global (US) API under Standard Contractual Clauses; the vendor does not train on API data; the provider does not currently offer an EU-region option for this model tier; every inference call logs its endpoint.
Encryption at rest
AES-256 (Supabase managed)
Encryption in transit
TLS 1.3 enforced
Authentication
Token-based authentication with per-customer access control enforced on every record
Backups
7-day Point-in-Time Recovery (Supabase Pro)
Audit logging
Tamper-evident records of every sensitive action, every control test and every piece of collected evidence. Corrections supersede; history is never rewritten
PII scrubbing
Sentry configured to strip all personal data fields
Access control
Role-based (Owner / Admin / Member) with RBAC
Webhook verification
Stripe webhook signatures verified on every request
AI System Transparency
EU AI Act Article 13 + Article 50 disclosure
Claude (Anthropic)
Model: claude-sonnet-5
Used for
- Compliance document generation (asynchronous, queued for processing)
- EU AI Act Article 5 prohibited practice screening
- Weekly and monthly executive report generation
- UAE Charter alignment assessment generation
Safeguards
- All AI-generated compliance documents carry a DRAFT watermark until reviewed by a qualified human
- No AI output is submitted to regulators without human sign-off
- AI responses are schema-validated before storage, and malformed output is rejected
- Max token limits enforced per document type to prevent runaway generation
- Every generated document is checked for unresolved placeholders and for citations that do not match the law it cites; where a second, independent system is configured, it re-derives the claims in that document and flags any discrepancy for the reviewer. A document that was not cross-checked is labelled as such, never presented as verified
Establishment & Supervisory Authority
GDPR Article 3 · EU-established
AM8 SASU is established in France, within the EU. As an EU-established controller, AM8 is not required to appoint an Article 27 EU representative. EU data subjects may lodge a complaint with their local supervisory authority or with the French CNIL.
Data protection: privacy@am8-ai-governance.tech
Lead authority: CNIL (Commission Nationale de l'Informatique et des Libertés) · cnil.fr
UK Data Subjects
UK GDPR
If you are in the United Kingdom, you may lodge a complaint with the UK Information Commissioner's Office (ICO). Where AM8 is required to appoint a UK Article 27 representative, those details will be published here.
Contact: privacy@am8-ai-governance.tech
ICO · ico.org.uk
Documents & Security Contact
Security Overview (one-pager)
For enterprise due diligence · request by email
Data Processing Agreement (DPA)
GDPR Article 28
Privacy Policy
GDPR Art. 13/14
Report a vulnerability: we welcome responsible disclosure. Email our security team at security@am8-ai-governance.tech and we will acknowledge your report within two business days.
For data protection enquiries contact privacy@am8-ai-governance.tech. AM8 is a product of AM8 SASU, registered in France.