AI proposes. Evidence verifies. Your responsible people decide.
We do not present a prototype as a transformation, or a projection as a realised saving. The wording below is deliberately careful: readiness is not certification, and we will not claim otherwise.
“Readiness” and “control alignment” describe how we work; they are not a claim of certification or legal compliance. SOC 2 is a voluntary assurance framework, not a law. Duties under the UK/EU AI Act depend on your role, system and market, and are not identical for every company. Nothing on this page is a substitute for your own qualified legal advice.
Control domains we work to
A named use-case owner, intended purpose, prohibited uses and review frequency for every AI-assisted function we help you run.
Role-based access, least privilege and tenant isolation for any workspace we operate on your behalf.
Classification, minimisation, retention rules and deletion, agreed before any data flow is switched on.
An approved model/vendor register recording hosting region, training-use terms and an exit plan for each one in use.
Approval gates before material output is issued, a challenge route, and a named competent person responsible for it.
An incident route and a tamper-evident record of access, approvals and material state changes.
How we label a benefit claim
Every benefit figure in a roadmap or service review carries one of these labels, so you can see at a glance whether a number is a benchmark, an assumption or something your own finance function has confirmed.
Data and deployment choice
Local, cloud or hybrid deployment is chosen from your data classification and customer obligations during the roadmap stage, not promised in advance. No provider is selected because of a hoped-for referral or reseller arrangement; where one exists, it is disclosed to you.