AM8 Trust & Compliance
The only AI governance platform that passes the same audit it sells. Everything on this page is sourced from our own AM8 platform, updated automatically.
Last updated: 2026-07-21 · Platform v4.0
Certifications & Compliance
AM8 is built to the frameworks enterprise procurement and auditors ask for: GDPR, the EU AI Act, ISO 42001, SOC 2 and CSA STAR.
GDPR
EU & UK data protection
EU AI Act
Regulation 2024/1689
ISO 42001
AI management system (aligned)
SOC 2
Type II — in progress
CSA STAR
Cloud security self-assessment
EU AI Act Score
Article 9, 13, 17, 26, 43Scored 4 July 2026
Cookie Compliance
GDPR Art. 7 + ePrivacyALL GREEN
No non-consensual tracking detected
Powered by CookieYes · Scanned 2026-03-30
Continuous Control Monitoring
Live engine · computed 21 Jul 2026AM8 continuously tests itself against the same control catalog it sells — verdicts below are produced by the live engine, not hand-entered.
In-force posture
30/100
Upcoming readiness
50/100
Controls monitored
12
Passing / failing
3 / 6
| Control | Framework | Enforcement | Status |
|---|---|---|---|
Staff AI literacy coverage EU AI Act Article 4 | eu | In force | Passing |
No prohibited AI practices EU AI Act Article 5 | eu | In force | Passing |
Users are told they interact with AI EU AI Act Article 50 | eu | From Aug 2026 | Awaiting first test |
AI-generated content is labelled EU AI Act Article 50(2) | eu | From Dec 2026 | Failing — remediation open |
Serious incidents reported within SLA EU AI Act Article 73 | eu | From Dec 2027 | Passing |
All discovered AI systems are triaged EU AI Act Article 26 / governance · voluntary | eu | In force | Not applicable yet |
AI management system policy documented ISO/IEC 42001 (AIMS) · voluntary | iso42001 | In force | Awaiting first test |
Charter alignment assessment current UAE AI Charter (12 principles) · voluntary | uae | In force | Failing — remediation open |
DIFC transparency for AI-driven decisions DIFC Regulation 10 (in force Jan 2026) | uae | In force | Failing — remediation open |
Algorithmic bias assessment current UAE Charter Principle 3 (Fairness) + EU Art. 10 · voluntary | uae | In force | Failing — remediation open |
Automated decisions have a lawful basis and human-review path UAE PDPL Article 18 | uae | In force | Failing — remediation open |
PDPL processing record UAE PDPL (Federal Decree-Law 45/2021) | uae | In force | Failing — remediation open |
Verdicts are produced by AM8's own control-test engine over collected evidence — failing controls are shown honestly with remediation findings open. This is the same monitoring loop AM8 customers run.
Sub-Processor DPAs
GDPR Art. 28 · Updated 2026-07-21Data Processing Agreements signed with all sub-processors before any customer data was processed.
| Provider | Purpose | Data region | DPA status |
|---|---|---|---|
| Anthropic | AI processing (Claude API) | US | Signed |
| Supabase | Database, auth & storage | EU (Frankfurt) | Signed |
| Resend | Transactional email delivery | US | Signed |
| Stripe | Payment processing & billing | EU / US | Signed |
| Sentry | Error monitoring (PII-scrubbed) | US | Signed |
Security Controls
Data residency
EU Frankfurt (GDPR Art. 44–46 compliant)
Encryption at rest
AES-256 (Supabase managed)
Encryption in transit
TLS 1.3 enforced
Authentication
Supabase JWT + Row Level Security on all tables
Backups
7-day Point-in-Time Recovery (Supabase Pro)
Audit logging
pgaudit enabled — all data operations logged
PII scrubbing
Sentry configured to strip all personal data fields
Access control
Role-based (Owner / Admin / Member) with RBAC
Webhook verification
Stripe webhook signatures verified on every request
AI System Transparency
EU AI Act Article 13 + Article 50 disclosure
Claude (Anthropic)
Model: claude-sonnet-4-6
Used for
- Compliance document generation (async, queued via pg-boss)
- EU AI Act Article 5 prohibited practice screening
- Weekly and monthly executive report generation
- UAE Charter alignment assessment generation
Safeguards
- All AI-generated compliance documents carry a DRAFT watermark until reviewed by a qualified human
- No AI output is submitted to regulators without human sign-off
- AI responses are Zod-validated before storage — malformed output is rejected
- Max token limits enforced per document type to prevent runaway generation
Establishment & Supervisory Authority
GDPR Article 3 · EU-established
AM8 SASU is established in France, within the EU. As an EU-established controller, AM8 is not required to appoint an Article 27 EU representative. EU data subjects may lodge a complaint with their local supervisory authority or with the French CNIL.
Data protection: dpo@am8-ai-governance.tech
Lead authority: CNIL (Commission Nationale de l'Informatique et des Libertés) · cnil.fr
UK Data Subjects
UK GDPR
If you are in the United Kingdom, you may lodge a complaint with the UK Information Commissioner's Office (ICO). Where AM8 is required to appoint a UK Article 27 representative, those details will be published here.
Contact: dpo@am8-ai-governance.tech
ICO · ico.org.uk
Documents & Security Contact
Security Overview (one-pager)
For enterprise due diligence · PDF
Data Processing Agreement (DPA)
GDPR Article 28
Privacy Policy
GDPR Art. 13/14
Status & uptime
Real-time platform status
Report a vulnerability: we welcome responsible disclosure. Email our security team at security@am8-ai-governance.tech and we will acknowledge your report within two business days.
For data protection enquiries contact dpo@am8-ai-governance.tech. AM8 is a product of AM8 SASU, registered in France.