Procurement and security reviewers should not have to call sales to find this out. Each framework below carries the status of our work — nothing more, nothing implied.
Five today. The list grows as our obligations and our clients' obligations do.
Aligning our processing records, subprocessor list and retention rules with the Regulation, and keeping client data on EU-hosted infrastructure by default.
Mapping the AI systems we build and operate against the Act's risk categories, and putting the documentation, logging and human-oversight practices the higher categories demand into our delivery process.
Reviewing our contracts, data-access provisions and switching terms against the Act, so client data stays portable and the exit path stays open.
Assessment preparation is under way — information-security controls are being documented and gaps closed ahead of an external assessment.
Building our information-security management system towards the ISO/IEC 27001 structure, with an external audit planned rather than behind us.
Each status above describes work in motion — not an achieved end state, and not an audited outcome. When that changes, this page changes with it, and only after the site owner has signed off on the new wording.
Tell us which framework and which control set your review covers, and we will send what we have today — including where the gaps still are.
Talk to us about your review