Live Compliance Scorecard

AM8 Trust & Compliance

The only AI governance platform that passes the same audit it sells. Everything on this page is sourced from our own AM8 platform, updated automatically.

Last updated: 2026-07-21 · Platform v4.0

Certifications & Compliance

AM8 is built to the frameworks enterprise procurement and auditors ask for: GDPR, the EU AI Act, ISO 42001, SOC 2 and CSA STAR.

GDPR

EU & UK data protection

EU AI Act

Regulation 2024/1689

ISO 42001

AI management system (aligned)

SOC 2

Type II — in progress

CSA STAR

Cloud security self-assessment

EU AI Act Score

Article 9, 13, 17, 26, 43
88/100
Below 90 publish threshold

Scored 4 July 2026

Cookie Compliance

GDPR Art. 7 + ePrivacy

ALL GREEN

No non-consensual tracking detected

Strictly necessary
Supabase auth sessionalways-on
Analytics
Gated behind consentopt-in
Marketing
Gated behind consentopt-in

Powered by CookieYes · Scanned 2026-03-30

Continuous Control Monitoring

Live engine · computed 21 Jul 2026

AM8 continuously tests itself against the same control catalog it sells — verdicts below are produced by the live engine, not hand-entered.

In-force posture

30/100

Upcoming readiness

50/100

Controls monitored

12

Passing / failing

3 / 6

ControlFrameworkEnforcementStatus

Staff AI literacy coverage

EU AI Act Article 4

euIn force Passing

No prohibited AI practices

EU AI Act Article 5

euIn force Passing

Users are told they interact with AI

EU AI Act Article 50

euFrom Aug 2026Awaiting first test

AI-generated content is labelled

EU AI Act Article 50(2)

euFrom Dec 2026 Failing — remediation open

Serious incidents reported within SLA

EU AI Act Article 73

euFrom Dec 2027 Passing

All discovered AI systems are triaged

EU AI Act Article 26 / governance · voluntary

euIn forceNot applicable yet

AI management system policy documented

ISO/IEC 42001 (AIMS) · voluntary

iso42001In forceAwaiting first test

Charter alignment assessment current

UAE AI Charter (12 principles) · voluntary

uaeIn force Failing — remediation open

DIFC transparency for AI-driven decisions

DIFC Regulation 10 (in force Jan 2026)

uaeIn force Failing — remediation open

Algorithmic bias assessment current

UAE Charter Principle 3 (Fairness) + EU Art. 10 · voluntary

uaeIn force Failing — remediation open

Automated decisions have a lawful basis and human-review path

UAE PDPL Article 18

uaeIn force Failing — remediation open

PDPL processing record

UAE PDPL (Federal Decree-Law 45/2021)

uaeIn force Failing — remediation open

Verdicts are produced by AM8's own control-test engine over collected evidence — failing controls are shown honestly with remediation findings open. This is the same monitoring loop AM8 customers run.

Sub-Processor DPAs

GDPR Art. 28 · Updated 2026-07-21

Data Processing Agreements signed with all sub-processors before any customer data was processed.

ProviderPurposeData regionDPA status
AnthropicAI processing (Claude API)US Signed
SupabaseDatabase, auth & storageEU (Frankfurt) Signed
ResendTransactional email deliveryUS Signed
StripePayment processing & billingEU / US Signed
SentryError monitoring (PII-scrubbed)US Signed

Security Controls

Data residency

EU Frankfurt (GDPR Art. 44–46 compliant)

Encryption at rest

AES-256 (Supabase managed)

Encryption in transit

TLS 1.3 enforced

Authentication

Supabase JWT + Row Level Security on all tables

Backups

7-day Point-in-Time Recovery (Supabase Pro)

Audit logging

pgaudit enabled — all data operations logged

PII scrubbing

Sentry configured to strip all personal data fields

Access control

Role-based (Owner / Admin / Member) with RBAC

Webhook verification

Stripe webhook signatures verified on every request

AI System Transparency

EU AI Act Article 13 + Article 50 disclosure

Claude (Anthropic)

Model: claude-sonnet-4-6

limited risk

Used for

  • Compliance document generation (async, queued via pg-boss)
  • EU AI Act Article 5 prohibited practice screening
  • Weekly and monthly executive report generation
  • UAE Charter alignment assessment generation

Safeguards

  • All AI-generated compliance documents carry a DRAFT watermark until reviewed by a qualified human
  • No AI output is submitted to regulators without human sign-off
  • AI responses are Zod-validated before storage — malformed output is rejected
  • Max token limits enforced per document type to prevent runaway generation
Article 50 disclosure: Content generated by Claude (Anthropic) is AI-assisted. All AI-generated compliance documents are clearly marked as DRAFT until reviewed by a qualified compliance professional. AM8 does not present AI output as certified legal advice.

Establishment & Supervisory Authority

GDPR Article 3 · EU-established

AM8 SASU is established in France, within the EU. As an EU-established controller, AM8 is not required to appoint an Article 27 EU representative. EU data subjects may lodge a complaint with their local supervisory authority or with the French CNIL.

Data protection: dpo@am8-ai-governance.tech

Lead authority: CNIL (Commission Nationale de l'Informatique et des Libertés) · cnil.fr

UK Data Subjects

UK GDPR

If you are in the United Kingdom, you may lodge a complaint with the UK Information Commissioner's Office (ICO). Where AM8 is required to appoint a UK Article 27 representative, those details will be published here.

Contact: dpo@am8-ai-governance.tech

ICO · ico.org.uk

Documents & Security Contact

Report a vulnerability: we welcome responsible disclosure. Email our security team at security@am8-ai-governance.tech and we will acknowledge your report within two business days.

For data protection enquiries contact dpo@am8-ai-governance.tech. AM8 is a product of AM8 SASU, registered in France.