The space is full of products that print certifications they have not earned. We are not one of them.
UK GDPR: live. AI Twin is designed and operated to comply with UK GDPR from the first user. Lawful basis, data minimisation, purpose limitation, storage limitation, integrity, confidentiality, accountability.
EU AI Act readiness: in build. We sit in the limited-risk category as we understand it today and are building toward the transparency, governance, and disclosure obligations. We are not yet formally assessed.
ISO 27001 and SOC 2: not yet certified. We are engineering toward both. They take time, they cost money, and they are worth doing properly. When we are independently audited, we will say so. Not before.
Sub-processors: our full public list of every third-party service that touches your data, with regions and DPA status, is at /sub-processors.
AI Twin is not a regulated legal, medical, or financial product. It does not replace your professional judgement, your firm's policy, or your regulator's guidance. It is the memory layer you would have built yourself if you had the time.