Trust Center
Trust you can audit, not just take on faith.
INSTRAT360 runs AI across leadership, sales, and product — so security, privacy, and human authority are part of the product, not later paperwork. This is where your security, legal, and DPO teams find what they need.
Six promises that make AI accountable
These hold across every product in the family, because they live in the shared governance layer — not in each app's settings.
Named accountability
Every consequential action requires a named approval. AI cannot approve its own work.
Full audit trail
Each AI action is logged with author, rationale, data used, and time — protected from ordinary modification.
Reversible by default
Applied changes carry a seven-day reversible window, so a mistake is recoverable rather than permanent.
EU data residency
Data is held in the EU with tenant isolation and least-privilege, role-scoped access down to the objective.
Encryption everywhere
Encryption in transit and at rest, secure secrets management, and strong authentication across every tenant.
No lock-in
Export your files, artifacts, audit history, and metadata at any time — and reproduce any approved decision.
Designed against the frameworks that matter in Europe
For AI that operates across the organization, compliance and information security are part of the product, not later documentation. One shared, compliance-ready foundation, with stricter controls activated by customer, data, and intended use.
- GDPRData protection & DPIA
- EU AI ActTransparency from Aug 2026
- NIS2Cybersecurity baseline
- DORAFinancial-services overlay
- EU Data ActSwitching & portability
- Cyber Resilience ActScope assessment
GDPR & data governance
Clear controller/processor roles, lawful-basis mapping, and full data-subject rights.
- Compliant DPA with controller/processor roles
- Data inventory, purpose limitation, and minimisation
- Explicit retention for chats, files, memory, and outputs
- Export, correction, and deletion of personal data
- Tenant isolation and least-privilege access
- Tested 72-hour incident-notification process
EU AI Act governance
Every AI capability records purpose, provider, data, evidence, owner, and approval.
- AI interaction and AI-assisted outputs clearly identified
- Recommendations kept distinct from verified facts
- AI cannot approve its own work
- Human approval required for consequential actions
- Stop, override, and correction supported
- Each domain classified before activation; prohibited uses blocked
Executive & financial controls
Deterministic math, canonical values, and immutable, reproducible decisions.
- Financial calculations use deterministic functions, not model guesses
- Forecasts, assumptions, and data-as-of dates are visible
- Narrative, tables, and charts use identical canonical values
- Read-only integration access by default
- External writes require explicit approval; maker–checker where needed
- Approved reports and decisions are immutable and reproducible
Cybersecurity & resilience
A NIS2-aligned baseline with a financial-services overlay for DORA scope.
- Strong authentication, role-based access, full tenant separation
- Encryption in transit and at rest; secure secrets
- Dependency and vulnerability management
- Audit logs protected from ordinary modification
- Backup, restore, and disaster-recovery tests
- Penetration testing and supplier/model-provider risk review
Customer control & portability
You see where data lives, control retention, and can export or exit at any time.
- See storage location, providers, subprocessors, and integrations
- Control retention and memory
- Disable any model, tool, employee, or automation
- Export files, artifacts, audit history, and metadata
- Delete the workspace with confirmation
- Reproduce any approved decision or deliverable — no lock-in
We build a compliance-ready foundation and require a formal DPO, legal, and security verification before deployment with real executive or customer data. Full compliance depends on the application, deployment, contracts, and each use case being aligned.
Governance you can see while you work
Trust is not a report we hand you at the end. It appears through the interface your team already uses.
- A Trust & Governance area in administration
- Inline classification and approval warnings
- Visible source, data, and AI provenance in outputs
- An audit and activity view
- Downloadable compliance evidence for auditors
Documentation and requests
Tell us what you need and we will route it to security, legal, or our data protection function.
Security & DPO requests
Data processing agreements, subprocessor lists, penetration-test summaries, and security questionnaires.
Data subject rights
Access, correction, export, or deletion of personal data held on your behalf.
Report a concern
Suspected incidents, vulnerabilities, or anything that needs a fast human response.