Skip to main content

Governance & Compliance

Built for regulated AI deployment

Where your data goes, which models touch it, who reviews the output, and what we will sign — answered on one page, so your security and procurement reviewers do not have to open a ticket to find out.

▸ PROCUREMENT SNAPSHOT

  • Deployed inside your cloud tenant — your data stays in infrastructure you own
  • No client data used to train models; no-training and zero-retention provider terms
  • Mutual NDA, DPA with SCCs, and a BAA where PHI is in scope
  • Deliverable IP — code, prompts, evaluations, documentation — assigned to you
DATA RESIDENCY

Your tenant

Agents run inside your cloud account or on-premise environment, under your identity and access management. We do not operate a multi-tenant platform that holds your production data.

MODEL TRAINING

No training

Your data is never used to train or fine-tune a model we ship to anyone else. We put no-training and zero-retention terms in place with model providers before any client data reaches an API.

AUDIT EVIDENCE

Included

Control mapping, test records, and oversight policies are engagement deliverables — not an extra your auditor has to request later.

01Regulatory Coverage

Frameworks we align to

Controls and documentation practices adapted to your deployment scope and risk profile.

01
Framework

EU AI Act

EU AI ACT

How we align controls

Risk-based classification of each use case, technical documentation discipline, defined human oversight, and lifecycle monitoring practices built into the system we deliver.

Focus area

Risk classification · lifecycle monitoring

02
Framework

GDPR

GDPR

How we align controls

Data minimization, lawful processing boundaries, privacy-by-design architecture, and operational controls for workflows that touch personal data. Backed contractually by a DPA with Standard Contractual Clauses.

Focus area

Data minimization · privacy by design

03
Framework

HIPAA

HIPAA

How we align controls

PHI-safe workflow design — minimum-necessary data flows, role-based access, and audit logging — delivered under BAA-backed terms whenever protected health information is in scope.

Focus area

PHI-safe workflows · access controls

04
Framework

SOC 2

SOC 2

How we align controls

Security, availability, and confidentiality control patterns applied to the systems we build inside your environment, documented so your auditor can test them. VelocityMind is not SOC 2 attested and does not issue attestations.

Focus area

Security · availability · audit

▸ OUR POSTURE, STATED PLAINLY

VelocityMind is an AI agent consultancy, not a certifying body and not an auditor. We hold no SOC 2 attestation and we do not issue one. What we provide is the control pattern, the implementation, and the evidence package: systems built to these frameworks inside your environment, documented so the auditor, regulator, or customer who asks can test them. Formal attestation and certification remain a matter between you and your assessor — we prepare what they ask for.

02Data Handling

Where your data goes

The first questions on every enterprise AI security questionnaire, answered before you have to send one.

01

Where does the system run?

Inside your cloud account or on-premise environment, under your IAM. We build, evaluate, and hand over; the running system and its data stay in infrastructure you own and can shut down without us.

02

Which model providers see our data?

Only the ones named in the architecture document you approve before build starts, with written routing rules for which class of data may reach which provider. Where a workflow cannot leave your boundary, we design it against self-hosted open-weight models instead.

03

Do you train models on our data?

No. Client data is never used to train or fine-tune a model delivered to another client, and provider accounts are configured for no-training and zero-retention terms before any of your data is sent.

04

Where is our data processed and stored?

In the deployment region you choose, written into the statement of work. We pin inference and storage to that region where the provider supports it; where it cannot be pinned, we redesign the step rather than route your data out of region.

05

Who are your sub-processors?

For this website: our hosting provider and our email delivery provider, both named in the Privacy Policy. On an engagement, no sub-processor touches client data without your prior written approval.

06

How are credentials and secrets handled?

You issue them, scoped to least privilege, held in your secret manager. We do not store client credentials in our own systems, and every access path is a named account you can revoke unilaterally.

07

What access do your people have?

Named individuals only, granted by you and logged in your environment. Access to production data is limited to what evaluation genuinely requires, in the smallest sample that answers the question.

08

What happens to our data when the engagement ends?

Working copies in our environment are returned or destroyed at handover and confirmed to you in writing. Source code, evaluation suites, and documentation live in your repositories from day one.

Anything above that needs to be stricter for your environment is scoped in the statement of work before build starts — not negotiated after go-live.

03Contractual Instruments

What we sign

The paperwork your legal and procurement teams will ask for, and when in the process it gets executed.

01 / 06

Mutual NDA

Signed before the first technical conversation — ours or your paper, whichever your legal team prefers.

02 / 06

MSA and fixed-scope SOW

Master terms agreed once; each engagement scoped in its own statement of work with named deliverables and written acceptance criteria.

03 / 06

Data Processing Agreement

GDPR Article 28 processor terms, with Standard Contractual Clauses and the UK Addendum where data moves outside the EEA or UK.

04 / 06

Business Associate Agreement

Executed before any design work that touches protected health information, where PHI is in scope.

05 / 06

IP assignment on payment

Source code, prompts, evaluation suites, and documentation assign to you on payment. Nothing you receive depends on a VelocityMind-hosted runtime.

06 / 06

Your vendor security assessment

We complete your standard questionnaire. Send specific clauses you need reviewed alongside the NDA and we will come back on them before kickoff.

04Control Tracks

How controls are applied in delivery

A practical model that combines policy alignment with operational execution.

01 / 04

Risk & Security Controls

Prompt-injection and tool abuse protection patterns
Role-based access, secrets management, and audit logging
Runtime guardrails for sensitive workflows
GUARDRAILS
02 / 04

Policy & Governance

Use-case risk classification and escalation framework
Human-in-the-loop checkpoints for high-impact decisions
Documented operating policies for AI-assisted workflows
POLICY
03 / 04

Model Risk & Evaluation

Evaluation suite with a written baseline agreed before go-live
Regression and drift testing on every model, prompt, or tool change
Documented failure modes, refusal behaviour, and reviewer escalation paths
EVALUATION
04 / 04

Monitoring & Oversight

Performance and quality drift tracking
Incident response and rollback pathways
Governance reviews tied to business KPIs
OVERSIGHT
05Evidence Package

Governance artifacts you receive

Deliverables designed for engineering, operations, and compliance stakeholders.

01AI use-case risk register and governance matrix
02Control mapping against the frameworks in scope for your deployment — selected during assessment
03Data-flow diagram and sub-processor register for your vendor file
04Operational policies for oversight, escalation, and approvals
05Human-in-the-loop and escalation specification, per workflow
06Evaluation suite, agreed baseline, and go-live test evidence
07Monitoring dashboard blueprint and alert thresholds
08Audit-ready implementation documentation package
06Get Started

Need an AI governance plan for your rollout?

We can map your target use cases, risk obligations, and control priorities in one focused strategy session.

No commitment · Response within one business day

▸ FOR SECURITY AND PROCUREMENT REVIEWERS

Running a vendor security assessment? Send us your questionnaire and we will complete it — or ask for the short version first.

▸ WHAT THE SESSION COVERS

  • Use-case mapping against the regulatory frameworks that actually apply to you
  • A prioritized control roadmap tied to your risk profile
  • Where your data would sit, and which model providers would be in scope
  • The artifact set your compliance team will receive