Trust & Compliance
Built for institutional scrutiny
Insurers, public institutions, and infrastructure operators cannot run on ambiguity. Every part of EOSYN Space, hosting, data governance, security headers, is built to survive an audit. Data control and regulatory compliance are not add-ons here. They are the starting point.
1. Security Standards
A zero-trust architecture with layered controls from edge to compute to storage. No single point grants broad access.
- TLS 1.3 everywhere
- HSTS preload enabled
- Strict Content Security Policy
- Full security header suite
- Zero-trust network architecture
- Bi-annual third-party penetration testing
- Public bug bounty via HackerOne
- Cloudflare WAF at the edge
- HashiCorp Vault for secrets management
- Microsoft Sentinel SIEM
- SOC 2 Type II roadmap
- ISO 27001 roadmap
2. Data Governance
Storage stays regional, in the EU. Role-based access control gates every system. Every output carries provenance. Retention follows GDPR Article 17, and a Data Processing Agreement is available on request. PII gets field-level encryption.
| Classification | Examples | Encryption | Access Control | Logging |
|---|---|---|---|---|
| Public | Marketing content, docs | In transit (TLS 1.3) | Anonymous | Aggregate |
| Internal | Aggregated analytics, ops metrics | TLS 1.3 + AES-256 at rest | Authenticated staff | Access logs |
| Confidential | Customer data, model outputs | AES-256 at rest, field-level for PII | RBAC + MFA | Full audit trail |
| Restricted | Credentials, keys, DPA-scoped data | Vault-managed, HSM-backed | Break-glass approval | Immutable audit + SIEM alerts |
3. Hosting Architecture
EU-based cloud infrastructure sits behind a multi-CDN edge (Cloudflare and Fastly). Regional deployment options exist for customers who need them. High-security customers can request dedicated hosting through a special-purpose vehicle for complete isolation.
4. Auditability
Every prediction ships with the receipts an auditor asks for: calibration logs, confidence scores, provenance records tying outputs back to source imagery, model versioning, and exportable audit trails.
5. Regional Deployment
EU deployment is the default. US and UK regions are available, and hybrid setups suit customers spanning jurisdictions. AI compute residency is guaranteed through EU-region GPU instances.
6. Dual-Use & Export Controls
A structured product classification framework governs jurisdictional restrictions, export-control classification, and prohibitions on sales to restricted entities. It is built to comply fully with the EU dual-use regulation.
7. Civilian-Only Commitment
No government security contracts. No militarised language, ever. EOSYN Space serves civilian institutions only. This is a deliberate choice, not a limitation.
8. AI Governance & EU AI Act
EOSYN Space classifies every model against the EU AI Act, publishes model cards, and maintains a documented human-oversight framework. Post-market monitoring runs continuously, and every release goes through bias testing. Reach the AI Governance Lead at ai-governance@eosynspace.com.
| Product | EU AI Act Classification |
|---|---|
| EOSYN Core, Insurance | High-Risk (Annex III §5b) |
| EOSYN Core, Infrastructure | High-Risk (Annex III §2a) |
| EOSYN Core, Public Sector | Potentially high-risk (context-dependent) |
| EOSYN Atlas | Depends on downstream use |
9. Digital Environmental Responsibility
Every page loads under 0.2g of CO₂ per view, on green-verified hosting. Carbon-aware design choices, websitecarbon.com verification, and AI compute carbon measurement all feed into it. Residual emissions are offset.
10. Security Compliance Roadmap
- SOC 2 Type I6 months post-launch
- SOC 2 Type II12 months
- ISO 2700118 months
- Continuous pentestingOngoing, run by Cobalt.io
- Bug bountyOngoing, run via HackerOne