CNTRLD.AI
AI Decision Assurance AI Trust Center Enterprise Consumer Industries Request a briefing Start trial
Trust Center

Our assurance posture, stated plainly.

A company selling decision assurance should be willing to be examined on the same terms. This page sets out how we handle evidence, what standards we align to, what we claim, and what we do not.

Evidence and auditability

What is recorded, and what a record is good for.

Decision record

Each governed verdict is preserved with its outcome, stated confidence, the evidence relied upon, the governing policy, and the accountable authority.

Integrity of the record

Records are written so that later alteration is detectable. A record that could be quietly edited has no value in an audit or a proceeding.

Reproducibility

A verdict can be reconstructed as it stood at the time it was issued, rather than as the system would answer today.

Customer ownership

The evidence record belongs to the customer, is exportable, and is retained on the customer's schedule, not ours.

Regulatory alignment

We map to the frameworks our customers are held to.

Assurance is only useful if it speaks the language of the obligation. We maintain mappings from the decision record to the evidence expectations of the frameworks below, and we distinguish alignment from certification everywhere on this site.

EU AI Act NIST AI RMF ISO/IEC 42001 ISO/IEC 27001 SOC 2 criteria SR 11-7 model risk HIPAA GDPR

Framework names are used to describe the obligations we help customers evidence. Certification status, where applicable, is provided under NDA in the diligence package rather than asserted here.

Our claims discipline

What we will and will not say.

We state
What a governed verdict contains, and the conditions under which we withhold one. Which capabilities are in production, which are in validation, and which are on the roadmap, labeled as such. Alignment to a framework, with the specific evidence artifact that supports it.
We do not state
Detection rates, accuracy figures, or savings benchmarks we cannot attribute to a named source or a customer engagement. Roadmap capability described as though it were shipped. Certification, endorsement, or partnership we do not hold in writing.
Data and privacy

Minimum data, held for a stated reason.

Purpose limitation

Data is processed to reach and evidence a verdict. It is not used to train general models on customer or consumer content.

Consumer contexts

Household, elder, and minor contexts carry stricter handling, explicit consent expectations, and narrower escalation paths.

Residency and isolation

Deployment options cover regional residency and tenant isolation requirements. Specifics are confirmed in the security review for each engagement.

Vulnerability disclosure

Security findings can be reported directly to our team. We acknowledge, triage, and report back on a stated timeline.

Diligence materials on request.

Security questionnaires, architecture review under NDA, data processing terms, and current certification status are provided to prospective customers and partners through the diligence package.

Request diligence materials