- GDPR (EU)
- Residency enforced by deployment location. Right-to-erasure at the knowledge-graph layer. No personal-data processing outside the perimeter by default.
- EU AI Act
- High-risk AI controls via logging, human oversight gates, model documentation. Alignment in progress, targeting 2026.
- DORA (EU)
- Operational resilience via ICT-perimeter deployment, incident logging, third-party dependency minimisation.
- MiFID II / MAR
- Transaction surveillance, research-augmentation source attribution, audit reconstruction via decision-trace exports.
- Solvency II
- Prudential workflow via document intelligence and actuarial unification inside the regulated perimeter. On request per insurance carrier.
- ACPR / CNIL (France)
- French supervisory expectations via national hosting, data-processing records, DPO-ready audit exports.
- FINMA / CCAF (Switzerland)
- Swiss residency, secret bancaire posture, supervisory-review readiness via on-premise and Swiss-cloud deployment.
- CSSF (Luxembourg)
- Luxembourg requirements via regional deployment and outsourcing-arrangement documentation.
- Bank Al-Maghrib / Loi 09-08 (Morocco)
- National hosting, Moroccan residency, central-bank reporting via local deployment.
- PDPL (UAE)
- UAE residency and data-protection via regional deployment. Central Bank UAE alignment on request.
- HIPAA (US)
- PHI inside the provider's perimeter. BAA-compatible deployment. US-region hosting on request.
- GDPR health provisions (EU)
- Special-category health data within the hospital perimeter — consent and access logs exposed to the DPO.
- GxP (pharma)
- Audit traceability, model-version pinning, prompt/response archival for regulatory-submission and quality workflows.
- SOC 2
- Type II audit underway, targeting 2026.
- National sovereign-cloud requirements
- Deployment on certified sovereign-cloud providers via the national or private-cloud mode. Accreditations vary by country.