Trust Center

Trust you can audit, not just take on faith.

INSTRAT360 runs AI across leadership, sales, and product — so security, privacy, and human authority are part of the product, not later paperwork. This is where your security, legal, and DPO teams find what they need.

Privacy policy
Core commitments

Six promises that make AI accountable

These hold across every product in the family, because they live in the shared governance layer — not in each app's settings.

Compliance by design

Designed against the frameworks that matter in Europe

For AI that operates across the organization, compliance and information security are part of the product, not later documentation. One shared, compliance-ready foundation, with stricter controls activated by customer, data, and intended use.

  • GDPRData protection & DPIA
  • EU AI ActTransparency from Aug 2026
  • NIS2Cybersecurity baseline
  • DORAFinancial-services overlay
  • EU Data ActSwitching & portability
  • Cyber Resilience ActScope assessment

GDPR & data governance

Clear controller/processor roles, lawful-basis mapping, and full data-subject rights.

  • Compliant DPA with controller/processor roles
  • Data inventory, purpose limitation, and minimisation
  • Explicit retention for chats, files, memory, and outputs
  • Export, correction, and deletion of personal data
  • Tenant isolation and least-privilege access
  • Tested 72-hour incident-notification process

EU AI Act governance

Every AI capability records purpose, provider, data, evidence, owner, and approval.

  • AI interaction and AI-assisted outputs clearly identified
  • Recommendations kept distinct from verified facts
  • AI cannot approve its own work
  • Human approval required for consequential actions
  • Stop, override, and correction supported
  • Each domain classified before activation; prohibited uses blocked

Executive & financial controls

Deterministic math, canonical values, and immutable, reproducible decisions.

  • Financial calculations use deterministic functions, not model guesses
  • Forecasts, assumptions, and data-as-of dates are visible
  • Narrative, tables, and charts use identical canonical values
  • Read-only integration access by default
  • External writes require explicit approval; maker–checker where needed
  • Approved reports and decisions are immutable and reproducible

Cybersecurity & resilience

A NIS2-aligned baseline with a financial-services overlay for DORA scope.

  • Strong authentication, role-based access, full tenant separation
  • Encryption in transit and at rest; secure secrets
  • Dependency and vulnerability management
  • Audit logs protected from ordinary modification
  • Backup, restore, and disaster-recovery tests
  • Penetration testing and supplier/model-provider risk review

Customer control & portability

You see where data lives, control retention, and can export or exit at any time.

  • See storage location, providers, subprocessors, and integrations
  • Control retention and memory
  • Disable any model, tool, employee, or automation
  • Export files, artifacts, audit history, and metadata
  • Delete the workspace with confirmation
  • Reproduce any approved decision or deliverable — no lock-in

We build a compliance-ready foundation and require a formal DPO, legal, and security verification before deployment with real executive or customer data. Full compliance depends on the application, deployment, contracts, and each use case being aligned.

In the product

Governance you can see while you work

Trust is not a report we hand you at the end. It appears through the interface your team already uses.

Reach the right team

Documentation and requests

Tell us what you need and we will route it to security, legal, or our data protection function.

  • Security & DPO requests

    Data processing agreements, subprocessor lists, penetration-test summaries, and security questionnaires.

  • Data subject rights

    Access, correction, export, or deletion of personal data held on your behalf.

  • Report a concern

    Suspected incidents, vulnerabilities, or anything that needs a fast human response.