Governance & Compliance
Built for regulated AI deployment
Where your data goes, which models touch it, who reviews the output, and what we will sign — answered on one page, so your security and procurement reviewers do not have to open a ticket to find out.
▸ PROCUREMENT SNAPSHOT
- Deployed inside your cloud tenant — your data stays in infrastructure you own
- No client data used to train models; no-training and zero-retention provider terms
- Mutual NDA, DPA with SCCs, and a BAA where PHI is in scope
- Deliverable IP — code, prompts, evaluations, documentation — assigned to you
Your tenant
Agents run inside your cloud account or on-premise environment, under your identity and access management. We do not operate a multi-tenant platform that holds your production data.
No training
Your data is never used to train or fine-tune a model we ship to anyone else. We put no-training and zero-retention terms in place with model providers before any client data reaches an API.
Included
Control mapping, test records, and oversight policies are engagement deliverables — not an extra your auditor has to request later.
Frameworks we align to
Controls and documentation practices adapted to your deployment scope and risk profile.
EU AI Act
EU AI ACT
Risk-based classification of each use case, technical documentation discipline, defined human oversight, and lifecycle monitoring practices built into the system we deliver.
Risk classification · lifecycle monitoring
GDPR
GDPR
Data minimization, lawful processing boundaries, privacy-by-design architecture, and operational controls for workflows that touch personal data. Backed contractually by a DPA with Standard Contractual Clauses.
Data minimization · privacy by design
HIPAA
HIPAA
PHI-safe workflow design — minimum-necessary data flows, role-based access, and audit logging — delivered under BAA-backed terms whenever protected health information is in scope.
PHI-safe workflows · access controls
SOC 2
SOC 2
Security, availability, and confidentiality control patterns applied to the systems we build inside your environment, documented so your auditor can test them. VelocityMind is not SOC 2 attested and does not issue attestations.
Security · availability · audit
▸ OUR POSTURE, STATED PLAINLY
VelocityMind is an AI agent consultancy, not a certifying body and not an auditor. We hold no SOC 2 attestation and we do not issue one. What we provide is the control pattern, the implementation, and the evidence package: systems built to these frameworks inside your environment, documented so the auditor, regulator, or customer who asks can test them. Formal attestation and certification remain a matter between you and your assessor — we prepare what they ask for.
Where your data goes
The first questions on every enterprise AI security questionnaire, answered before you have to send one.
Where does the system run?
Inside your cloud account or on-premise environment, under your IAM. We build, evaluate, and hand over; the running system and its data stay in infrastructure you own and can shut down without us.
Which model providers see our data?
Only the ones named in the architecture document you approve before build starts, with written routing rules for which class of data may reach which provider. Where a workflow cannot leave your boundary, we design it against self-hosted open-weight models instead.
Do you train models on our data?
No. Client data is never used to train or fine-tune a model delivered to another client, and provider accounts are configured for no-training and zero-retention terms before any of your data is sent.
Where is our data processed and stored?
In the deployment region you choose, written into the statement of work. We pin inference and storage to that region where the provider supports it; where it cannot be pinned, we redesign the step rather than route your data out of region.
Who are your sub-processors?
For this website: our hosting provider and our email delivery provider, both named in the Privacy Policy. On an engagement, no sub-processor touches client data without your prior written approval.
How are credentials and secrets handled?
You issue them, scoped to least privilege, held in your secret manager. We do not store client credentials in our own systems, and every access path is a named account you can revoke unilaterally.
What access do your people have?
Named individuals only, granted by you and logged in your environment. Access to production data is limited to what evaluation genuinely requires, in the smallest sample that answers the question.
What happens to our data when the engagement ends?
Working copies in our environment are returned or destroyed at handover and confirmed to you in writing. Source code, evaluation suites, and documentation live in your repositories from day one.
Anything above that needs to be stricter for your environment is scoped in the statement of work before build starts — not negotiated after go-live.
What we sign
The paperwork your legal and procurement teams will ask for, and when in the process it gets executed.
Mutual NDA
Signed before the first technical conversation — ours or your paper, whichever your legal team prefers.
MSA and fixed-scope SOW
Master terms agreed once; each engagement scoped in its own statement of work with named deliverables and written acceptance criteria.
Data Processing Agreement
GDPR Article 28 processor terms, with Standard Contractual Clauses and the UK Addendum where data moves outside the EEA or UK.
Business Associate Agreement
Executed before any design work that touches protected health information, where PHI is in scope.
IP assignment on payment
Source code, prompts, evaluation suites, and documentation assign to you on payment. Nothing you receive depends on a VelocityMind-hosted runtime.
Your vendor security assessment
We complete your standard questionnaire. Send specific clauses you need reviewed alongside the NDA and we will come back on them before kickoff.
How controls are applied in delivery
A practical model that combines policy alignment with operational execution.
Risk & Security Controls
Policy & Governance
Model Risk & Evaluation
Monitoring & Oversight
Governance artifacts you receive
Deliverables designed for engineering, operations, and compliance stakeholders.
Need an AI governance plan for your rollout?
We can map your target use cases, risk obligations, and control priorities in one focused strategy session.
No commitment · Response within one business day
▸ FOR SECURITY AND PROCUREMENT REVIEWERS
Running a vendor security assessment? Send us your questionnaire and we will complete it — or ask for the short version first.
▸ WHAT THE SESSION COVERS
- Use-case mapping against the regulatory frameworks that actually apply to you
- A prioritized control roadmap tied to your risk profile
- Where your data would sit, and which model providers would be in scope
- The artifact set your compliance team will receive