Start Free

Governance Is Now Law.

Overview

Our Regulatory Position

How the EU AI Act applies, and where CARDIAC-PURR AI Control Plane stands under it.

01

Regulation

The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) creates binding obligations for organisations deploying AI in regulated sectors.

02

Our Position

CARDIAC-PURR operates as a prompt routing and cost-governance layer. It does not make consequential decisions on behalf of natural persons and does not fall within any listed high-risk category under Annex III of the EU AI Act.

Status

Compliance Status Matrix

ArticleRequirementStatusNotes
6Risk classificationCompletedDetermination completed 25 June 2026 — non-high-risk; Annex III does not apply
9Risk management systemIn progress
10Data and data governanceIn progressNo training data used by the routing system; classification uses deterministic keyword/marker matching against a fixed ruleset, not a trained model
11Technical documentationIn progressSee Article 18
12Record-keeping and loggingIn progressLog retention period to be confirmed
13Transparency to deployersIn progressDeployer information package under preparation
14Human oversightIn progressSee below
15Accuracy, robustness, cybersecurityIn progressValidated on a 100-query, 4-vertical enterprise benchmark across nine provider integrations, used for testing purposes — the platform itself works with any LLM provider — see Benchmarks
16Quality management systemIn progress
17QMS specificsIn progress
18Technical documentationIn progress
19Automatic loggingIn progress
43Conformity assessmentNot applicableApplies only to high-risk systems; not applicable per Section 3 self-assessment
47EU declaration of conformityNot applicableSame basis
48CE markingNot applicableSame basis
49EU database registrationIn progressRegistration obligation under Art. 49(2) has not yet matured; will register if required

Detail

Regulatory Detail, Article by Article

Article 14

Human Oversight

Human oversight requires that natural persons can understand the system's capabilities and limitations, monitor its operation in real time, and intervene or override automated routing decisions. Automated fallback chains are a reliability feature — they do not, by themselves, constitute human oversight under Article 14.

CARDIAC-PURR AI Control Plane provides authorised operators with a real-time operator dashboard and OpenTelemetry-compatible telemetry pipeline. Operators can review full provenance metadata per response, identify anomalies, and intervene or halt execution through the platform API. A structured audit trail is maintained automatically.

Article 26

Deployer Obligations

Integrating the CARDIAC-PURR AI Control Plane into a product operating in a regulated sector means you assume deployer obligations under Article 26 — ensuring your specific use case complies with the Act, implementing context-appropriate human oversight, and restricting use to its intended purpose.

Deployers remain independently responsible for their own Article 26 compliance and any fundamental rights impact assessment under Article 27.

Article 53

General-Purpose AI Models

CARDIAC-PURR AI Control Plane routes prompts to third-party general-purpose AI models. It does not train, fine-tune, or place those models on the market, and does not assume provider obligations under Chapter V for the underlying GPAI models. Confirm GPAI compliance status directly with each model provider.

GDPR

Data Protection

Where routing involves personal data in prompts, that processing is subject to GDPR concurrently with the AI Act. CARDIAC-PURR AI Control Plane processes routing metadata only and does not retain prompt content beyond the routing operation. Personal or sensitive data is not passed through to providers in a way that exposes it unnecessarily. Deployers are responsible for establishing a lawful basis for prompt processing.

Timeline

Regulatory Timeline

2 August 2025
GPAI obligations became applicable.
2 August 2026
Article 50 transparency obligations apply.
2 December 2026
Limited grace period ends for certain AI-generated-content marking and detection obligations for systems placed on the market before 2 August 2026.
2 December 2027
High-risk obligations for standalone Annex III systems apply under the current AI Act timeline as amended by the AI Omnibus.
2 August 2028
High-risk AI rules for systems embedded in regulated products under Annex I apply.

Operations

Service Level & Security

Uptime Commitment

99.5% monthly target. If uptime falls below 99.0% in a given month, the remedy is termination for convenience with 30 days' notice, following a cure period — not automatic service credits. Service credits are available only under an optional negotiated Schedule C.

Data Residency

Primary hosting is in Frankfurt, EU, with US hosting available as an option on request. Where data leaves the EEA, transfers are governed by EU Standard Contractual Clauses.

Security Controls

TLS 1.2+ encryption in transit, access controls, continuous monitoring and logging, vulnerability management, incident response procedures, and a security-incident notification commitment.

Certifications

ISO 27001 — target Q4 2026
SOC 2 Type I — target Q1 2027
Neither is complete yet — treat both as roadmap items, not current certifications.

FAQ

Common Questions.

Who is the legal entity behind CARDIAC-PURR AI Control Plane?

2info Sp. z o.o. (2info LLC), Krakow, Poland.

Does using CARDIAC-PURR AI Control Plane make us EU AI Act compliant automatically?

No. This page describes ongoing compliance work under Regulation (EU) 2024/1689. It does not constitute legal advice, a conformity declaration, or a claim of compliance with any specific obligation. Organisations should conduct their own legal assessment.

Do you have SOC 2 or ISO 27001?

See Service Level & Security above — both are in progress, with target dates, not yet complete: ISO 27001 targets Q4 2026, SOC 2 Type I targets Q1 2027.

Where is data hosted, and does it stay in the EU?

Primary hosting is in Frankfurt, EU, with US hosting available on request. Where data leaves the EEA, transfers are governed by EU Standard Contractual Clauses.

What's the uptime commitment?

99.5% monthly target. If uptime falls below 99.0% in a given month, the remedy is termination for convenience with 30 days' notice following a cure period — not automatic service credits. Service credits are available only under an optional negotiated Schedule C.

What security controls are in place today?

TLS 1.2+ encryption in transit, access controls, continuous monitoring and logging, vulnerability management, incident response procedures, and a security-incident notification commitment.

Do you retain our prompt data?

CARDIAC-PURR AI Control Plane processes routing metadata only and does not retain prompt content beyond the routing operation. Personal or sensitive data is not passed through to providers in a way that exposes it unnecessarily. Deployers remain responsible for establishing a lawful basis for prompt processing under GDPR.

Are you responsible for the underlying model providers' own AI Act obligations?

No. CARDIAC-PURR AI Control Plane routes prompts to third-party general-purpose AI models under Article 53 — it does not train, fine-tune, or place those models on the market, and does not assume provider obligations under Chapter V. Confirm GPAI compliance status directly with each model provider.

Do you offer a Business Associate Agreement (BAA) for HIPAA-covered customers?

No. HIPAA-specific compliance claims, including a BAA, are not offered on the current platform — this was a deliberate removal, not an oversight.

Does CARDIAC-PURR AI Control Plane ever use our prompts or responses to improve the product, train models, or for any purpose beyond serving the request?

No. As stated on the Platform page: the platform requires no training at all, by design. Routing metadata is processed to make and audit routing decisions; prompt content itself is not retained beyond the routing operation and is not used to train or fine-tune anything.

Is data encrypted at rest as well as in transit?

In transit: TLS 1.2+, confirmed. At-rest encryption specifics (e.g. algorithm, key management) are not yet documented.

Do you support role-based access control and audit logs for who accessed what?

Yes — role-based access control is implemented and verified, alongside a real-time dashboard with full per-response provenance metadata and a structured audit trail (see Article 14 above). Granular per-user vs. per-team vs. per-API-key role definitions are not yet publicly documented in detail.

Can prompt/response logging be selectively disabled per request or per key?

Not explicitly documented. What's confirmed is that prompt content itself is not retained beyond the routing operation; whether logging behaviour is separately configurable per request or key is not yet publicly documented.

How long is data retained, and is retention configurable?

For customers under a signed enterprise agreement: Customer Data is deleted or irreversibly anonymised within 30 days of termination or expiry, except where retention is legally required, needed for billing records, or under an active legal hold. Where the Service is classified as high-risk under the EU AI Act, logs are retained for the legally mandated 6-month floor. Whether retention periods are further configurable below these defaults is not yet documented.

What's the incident response and breach notification process?

For customers under a signed enterprise agreement: notification within 24 hours of a confirmed security incident affecting Customer Data, including a description of the incident, the data types affected, containment steps taken, and recommended mitigation. Whether this same 24-hour commitment applies uniformly to self-serve customers without a signed agreement is not yet publicly documented.

Do you undergo third-party security audits or penetration testing?

Not yet — a formal penetration-testing program is on the roadmap, not in place today.

Discuss current compliance documentation →