Governance & Security

Every material action: policy-gated, reviewed, approved, on the record.

This page is written for the people who sign: risk, compliance and IT. Every claim below names its mechanism - and where an artifact exists, you can read it before you commit.

How every action runs

Two gates. No exceptions for material actions.

STEP 01

Finding

A case needs a decision - context assembles from your systems.

STEP 02

Agent review

Specialist analyses challenge the recommendation - policy, compliance, evidence.

GATE 1
STEP 03

Consensus

A structured verdict - rationale, disagreements, unresolved evidence.

STEP 04

Human approval

The named quality, clearing or compliance owner decides. Nothing runs without this.

GATE 2
STEP 05

Execution

Only approved actions execute in your systems - logged and signed.

logged · signed
The controls

Human authority built in - not bolted on.

Authority rules

Approval limits, spend authority, referrals, exceptions and escalation - encoded as policy and enforced at the approval gate, not written in a handbook.

Review & challenge

Independent agent review challenges every material recommendation - policy, compliance, evidence and quality - before it reaches a human.

Named human approval

Every material action routes to a named accountable person with the authority to decide it. No anonymous approvals, no silent execution.

Hash-chained audit history

Evidence, recommendation, challenge, approval, action and outcome are recorded in a hash-chained history - reproducible for any case, exportable for any audit.

Autonomy levels & revocation

Low-risk repeatable patterns earn automation on measured performance. Your critical actions never graduate. One bad outcome revokes autonomy - with retro-review of the autonomous window.

Evaluation framework

Case-level accuracy, completeness, escalation quality, latency, human acceptance and business outcomes - measured against a baseline agreed before every shift.

The centerpiece artifact

The Materiality & Gates Specification.

A short normative document - public, not marketing. It defines materiality default-deny: any action that writes to a system of record, communicates externally, commits money or coverage, or touches personal data is material and human-gated unless explicitly whitelisted by a named customer role under four-eyes. It states the exact two-gate semantics (agent challenge gate, then named-human gate), the autonomy graduation and revocation governance including the customer-locked always-human list, and a build-status column per control - present tense only where shipped.

The works-council commitment: the system evaluates agents, never employees - acceptance metrics are aggregated-only (minimum group size n≥5), with no per-user drill-down in product or exports, as a contractual product commitment.

Materiality & Gates Specification (PDF) - available on request
DACH procurement

DORA / VAIT outsourcing readiness, prepared.

Outsourcing review is the gate that blocks procurement in regulated sectors - so we prepare the file, as a readiness pack, not a compliance claim:

  • Outsourcing-readiness mapping for DORA / VAIT
  • DORA Art. 30 contract clauses prepared for your legal review
  • Audit rights including BaFin access
  • Exit and data-return plan
  • ICT-register language ready to paste
  • Subprocessor and model-provider chain, disclosed
  • Key-person clause for a two-founder vendor, stated plainly
EU AI Act

Evidence for your obligations - stated precisely.

The audit chain produces evidence supporting Art. 12 record-keeping, Art. 14 human oversight in operation, and your Art. 26 deployer obligations. Annex III high-risk obligations apply from 2 August 2026 - Annex III 5(c) explicitly covers risk assessment and pricing in life and health insurance. The provider/deployer role allocation (Art. 25) is stated in writing before any pilot touching underwriting.

What we never ask for

The boundary is permanent, not a phase.

Most vendors describe what they would like access to. This is the opposite: five categories we do not ask for, do not plan as a later stage, and do not renegotiate. It is part of the data processing agreement, so widening it would be a contract change you would have to sign — not a setting somebody adjusts.

  • Slack, Teams or e-mail content
  • Source code of any kind
  • Financial-system access
  • Any live or standing integration
  • Personnel files or performance data
The never-list (PDF)Take it to your works council before you commit to anything.
Deployment & data

Your data plane, your model estate.

Vendor-managed, EU-resident - with BYOM

The headline deployment: we operate an EU-resident instance, and bring-your-own-model routes every request into the model estate you already have agreements for - fail-closed, so a destination with no credential stops the request rather than falling back to one. Self-hosting remains a full capability for houses with their own operations team, on request.

GDPR-aligned architecture

Customer-managed keys, schema-per-tenant isolation, no training on customer data, and one-operation tenant erasure. We name the mechanisms - we never claim a certification or status we do not hold.

Hosting sheet (PDF)The never-list (PDF)Governance overview (PDF) - available on requestSample DPA (redacted) - available on request
For the people who sign

Hand your risk officer mechanisms and artifacts - not adjectives.

Governance & Security - every material action policy-gated, reviewed, approved, on the record · TeamIntel