Skip to main content

Trust & Compliance

Built for institutional scrutiny

Insurers, public institutions, and infrastructure operators cannot run on ambiguity. Every part of EOSYN Space, hosting, data governance, security headers, is built to survive an audit. Data control and regulatory compliance are not add-ons here. They are the starting point.

1. Security Standards

A zero-trust architecture with layered controls from edge to compute to storage. No single point grants broad access.

  • TLS 1.3 everywhere
  • HSTS preload enabled
  • Strict Content Security Policy
  • Full security header suite
  • Zero-trust network architecture
  • Bi-annual third-party penetration testing
  • Public bug bounty via HackerOne
  • Cloudflare WAF at the edge
  • HashiCorp Vault for secrets management
  • Microsoft Sentinel SIEM
  • SOC 2 Type II roadmap
  • ISO 27001 roadmap

2. Data Governance

Storage stays regional, in the EU. Role-based access control gates every system. Every output carries provenance. Retention follows GDPR Article 17, and a Data Processing Agreement is available on request. PII gets field-level encryption.

Data Classification Matrix
ClassificationExamplesEncryptionAccess ControlLogging
PublicMarketing content, docsIn transit (TLS 1.3)AnonymousAggregate
InternalAggregated analytics, ops metricsTLS 1.3 + AES-256 at restAuthenticated staffAccess logs
ConfidentialCustomer data, model outputsAES-256 at rest, field-level for PIIRBAC + MFAFull audit trail
RestrictedCredentials, keys, DPA-scoped dataVault-managed, HSM-backedBreak-glass approvalImmutable audit + SIEM alerts

3. Hosting Architecture

EU-based cloud infrastructure sits behind a multi-CDN edge (Cloudflare and Fastly). Regional deployment options exist for customers who need them. High-security customers can request dedicated hosting through a special-purpose vehicle for complete isolation.

4. Auditability

Every prediction ships with the receipts an auditor asks for: calibration logs, confidence scores, provenance records tying outputs back to source imagery, model versioning, and exportable audit trails.

5. Regional Deployment

EU deployment is the default. US and UK regions are available, and hybrid setups suit customers spanning jurisdictions. AI compute residency is guaranteed through EU-region GPU instances.

6. Dual-Use & Export Controls

A structured product classification framework governs jurisdictional restrictions, export-control classification, and prohibitions on sales to restricted entities. It is built to comply fully with the EU dual-use regulation.

7. Civilian-Only Commitment

No government security contracts. No militarised language, ever. EOSYN Space serves civilian institutions only. This is a deliberate choice, not a limitation.

8. AI Governance & EU AI Act

EOSYN Space classifies every model against the EU AI Act, publishes model cards, and maintains a documented human-oversight framework. Post-market monitoring runs continuously, and every release goes through bias testing. Reach the AI Governance Lead at ai-governance@eosynspace.com.

EU AI Act classification per product
ProductEU AI Act Classification
EOSYN Core, InsuranceHigh-Risk (Annex III §5b)
EOSYN Core, InfrastructureHigh-Risk (Annex III §2a)
EOSYN Core, Public SectorPotentially high-risk (context-dependent)
EOSYN AtlasDepends on downstream use

Read the model cards →·AI Ethics commitments →

9. Digital Environmental Responsibility

Every page loads under 0.2g of CO₂ per view, on green-verified hosting. Carbon-aware design choices, websitecarbon.com verification, and AI compute carbon measurement all feed into it. Residual emissions are offset.

Green hosting · ≤ 0.2g CO₂ / view

10. Security Compliance Roadmap

  1. SOC 2 Type I
    6 months post-launch
  2. SOC 2 Type II
    12 months
  3. ISO 27001
    18 months
  4. Continuous pentesting
    Ongoing, run by Cobalt.io
  5. Bug bounty
    Ongoing, run via HackerOne

Talk to us about your compliance requirements

Talk to our team