Most AI vendors treat compliance as a checklist to satisfy at procurement. We treat it as a design constraint, and we would rather tell you the limits up front than be found out at due diligence.
If your procurement process requires something in the right-hand column, tell us early. We would rather lose the work than misrepresent what we hold.
We move as little data as the use case requires, and design the flow around the requirement rather than the convenience of the tool.
Role-based access, least privilege and the authentication controls your organisation already operates.
A documented decision point wherever the output affects a person. AI assembles and flags. People decide.
Logging, change control and documentation, so an action can be evidenced months later rather than remembered.
Architecture chosen per use case, including deployment inside your own tenant where appropriate. Where a component cannot meet a residency requirement, we say so before building.
Every model provider and sub-processor named before build. Enterprise configurations that exclude your data from provider training. Deterministic rules wherever the logic is genuinely fixed.
Half the confusion in AI procurement comes from applying the wrong framework to the wrong party. This is how we read it.
Applies throughout. You are usually the controller, we are the processor or sub-processor, documented under Article 28.
Sets requirements for solely automated decisions with legal or similarly significant effects: transparency, human review and a right to contest. A designed-in decision point keeps most builds outside it.
An annual self-assessment by the organisation handling NHS data. We supply the evidence your submission needs. It is your submission, not ours.
0129 sits with the manufacturer, 0160 with the deploying organisation. We produce the safety documentation and work alongside your Clinical Safety Officer.
Applies only where a system is placed on the EU market or its output is used in the EU. UK-only operations are generally outside scope. We confirm at scoping rather than assume.
Applied to how patient-identifiable information is justified, minimised and accessed in any build that touches it.
There is no dedicated UK AI Act. AI use in the UK is governed through existing law and sector regulation, which is why data protection and clinical governance do most of the work here.
You own the bespoke workflows, applications and systems we deliver, subject to any underlying third-party platform licences.
We do not retain your data on our own infrastructure as a matter of course. Return and deletion are agreed in the contract.
Handover includes the documentation needed to run, audit and change the system without us.
We would rather answer it in twenty minutes now than in a due diligence pack in three months. If the answer is no, you will get a no.