Governance Is Now Law.
Overview
Our Regulatory Position
How the EU AI Act applies, and where CARDIAC-PURR AI Control Plane stands under it.
Regulation
The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) creates binding obligations for organisations deploying AI in regulated sectors.
Our Position
CARDIAC-PURR operates as a prompt routing and cost-governance layer. It does not make consequential decisions on behalf of natural persons and does not fall within any listed high-risk category under Annex III of the EU AI Act.
Article 6 Assessment
The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) creates binding obligations for organisations deploying AI in regulated sectors. 2info LLC has conducted a formal self-assessment under Article 6 and concluded that CARDIAC-PURR does not fall within any Annex III high-risk use case. A written Article 6 classification determination was completed on 25 June 2026 and incorporated into the Article 18 technical documentation.
Status
Compliance Status Matrix
| Article | Requirement | Status | Notes |
|---|---|---|---|
| 6 | Risk classification | Completed | Determination completed 25 June 2026 — non-high-risk; Annex III does not apply |
| 9 | Risk management system | In progress | |
| 10 | Data and data governance | In progress | No training data used by the routing system; classification uses deterministic keyword/marker matching against a fixed ruleset, not a trained model |
| 11 | Technical documentation | In progress | See Article 18 |
| 12 | Record-keeping and logging | In progress | Log retention period to be confirmed |
| 13 | Transparency to deployers | In progress | Deployer information package under preparation |
| 14 | Human oversight | In progress | See below |
| 15 | Accuracy, robustness, cybersecurity | In progress | Validated on a 100-query, 4-vertical enterprise benchmark across nine provider integrations, used for testing purposes — the platform itself works with any LLM provider — see Benchmarks |
| 16 | Quality management system | In progress | |
| 17 | QMS specifics | In progress | |
| 18 | Technical documentation | In progress | |
| 19 | Automatic logging | In progress | |
| 43 | Conformity assessment | Not applicable | Applies only to high-risk systems; not applicable per Section 3 self-assessment |
| 47 | EU declaration of conformity | Not applicable | Same basis |
| 48 | CE marking | Not applicable | Same basis |
| 49 | EU database registration | In progress | Registration obligation under Art. 49(2) has not yet matured; will register if required |
Detail
Regulatory Detail, Article by Article
Article 14
Human Oversight
Human oversight requires that natural persons can understand the system's capabilities and limitations, monitor its operation in real time, and intervene or override automated routing decisions. Automated fallback chains are a reliability feature — they do not, by themselves, constitute human oversight under Article 14.
CARDIAC-PURR AI Control Plane provides authorised operators with a real-time operator dashboard and OpenTelemetry-compatible telemetry pipeline. Operators can review full provenance metadata per response, identify anomalies, and intervene or halt execution through the platform API. A structured audit trail is maintained automatically.
Article 26
Deployer Obligations
Integrating the CARDIAC-PURR AI Control Plane into a product operating in a regulated sector means you assume deployer obligations under Article 26 — ensuring your specific use case complies with the Act, implementing context-appropriate human oversight, and restricting use to its intended purpose.
Deployers remain independently responsible for their own Article 26 compliance and any fundamental rights impact assessment under Article 27.
Article 53
General-Purpose AI Models
CARDIAC-PURR AI Control Plane routes prompts to third-party general-purpose AI models. It does not train, fine-tune, or place those models on the market, and does not assume provider obligations under Chapter V for the underlying GPAI models. Confirm GPAI compliance status directly with each model provider.
GDPR
Data Protection
Where routing involves personal data in prompts, that processing is subject to GDPR concurrently with the AI Act. CARDIAC-PURR AI Control Plane processes routing metadata only and does not retain prompt content beyond the routing operation. Personal or sensitive data is not passed through to providers in a way that exposes it unnecessarily. Deployers are responsible for establishing a lawful basis for prompt processing.
Timeline
Regulatory Timeline
Operations
Service Level & Security
Uptime Commitment
99.5% monthly target. If uptime falls below 99.0% in a given month, the remedy is termination for convenience with 30 days' notice, following a cure period — not automatic service credits. Service credits are available only under an optional negotiated Schedule C.
Data Residency
Primary hosting is in Frankfurt, EU, with US hosting available as an option on request. Where data leaves the EEA, transfers are governed by EU Standard Contractual Clauses.
Security Controls
TLS 1.2+ encryption in transit, access controls, continuous monitoring and logging, vulnerability management, incident response procedures, and a security-incident notification commitment.
Certifications
ISO 27001 — target Q4 2026
SOC 2 Type I — target Q1 2027
Neither is complete yet — treat both as roadmap items, not current certifications.
FAQ
Common Questions.
Who is the legal entity behind CARDIAC-PURR AI Control Plane?
2info Sp. z o.o. (2info LLC), Krakow, Poland.
Does using CARDIAC-PURR AI Control Plane make us EU AI Act compliant automatically?
No. This page describes ongoing compliance work under Regulation (EU) 2024/1689. It does not constitute legal advice, a conformity declaration, or a claim of compliance with any specific obligation. Organisations should conduct their own legal assessment.
Do you have SOC 2 or ISO 27001?
See Service Level & Security above — both are in progress, with target dates, not yet complete: ISO 27001 targets Q4 2026, SOC 2 Type I targets Q1 2027.
Where is data hosted, and does it stay in the EU?
Primary hosting is in Frankfurt, EU, with US hosting available on request. Where data leaves the EEA, transfers are governed by EU Standard Contractual Clauses.
What's the uptime commitment?
99.5% monthly target. If uptime falls below 99.0% in a given month, the remedy is termination for convenience with 30 days' notice following a cure period — not automatic service credits. Service credits are available only under an optional negotiated Schedule C.
What security controls are in place today?
TLS 1.2+ encryption in transit, access controls, continuous monitoring and logging, vulnerability management, incident response procedures, and a security-incident notification commitment.
Do you retain our prompt data?
CARDIAC-PURR AI Control Plane processes routing metadata only and does not retain prompt content beyond the routing operation. Personal or sensitive data is not passed through to providers in a way that exposes it unnecessarily. Deployers remain responsible for establishing a lawful basis for prompt processing under GDPR.
Are you responsible for the underlying model providers' own AI Act obligations?
No. CARDIAC-PURR AI Control Plane routes prompts to third-party general-purpose AI models under Article 53 — it does not train, fine-tune, or place those models on the market, and does not assume provider obligations under Chapter V. Confirm GPAI compliance status directly with each model provider.
Do you offer a Business Associate Agreement (BAA) for HIPAA-covered customers?
No. HIPAA-specific compliance claims, including a BAA, are not offered on the current platform — this was a deliberate removal, not an oversight.
Does CARDIAC-PURR AI Control Plane ever use our prompts or responses to improve the product, train models, or for any purpose beyond serving the request?
No. As stated on the Platform page: the platform requires no training at all, by design. Routing metadata is processed to make and audit routing decisions; prompt content itself is not retained beyond the routing operation and is not used to train or fine-tune anything.
Is data encrypted at rest as well as in transit?
In transit: TLS 1.2+, confirmed. At-rest encryption specifics (e.g. algorithm, key management) are not yet documented.
Do you support role-based access control and audit logs for who accessed what?
Yes — role-based access control is implemented and verified, alongside a real-time dashboard with full per-response provenance metadata and a structured audit trail (see Article 14 above). Granular per-user vs. per-team vs. per-API-key role definitions are not yet publicly documented in detail.
Can prompt/response logging be selectively disabled per request or per key?
Not explicitly documented. What's confirmed is that prompt content itself is not retained beyond the routing operation; whether logging behaviour is separately configurable per request or key is not yet publicly documented.
How long is data retained, and is retention configurable?
For customers under a signed enterprise agreement: Customer Data is deleted or irreversibly anonymised within 30 days of termination or expiry, except where retention is legally required, needed for billing records, or under an active legal hold. Where the Service is classified as high-risk under the EU AI Act, logs are retained for the legally mandated 6-month floor. Whether retention periods are further configurable below these defaults is not yet documented.
What's the incident response and breach notification process?
For customers under a signed enterprise agreement: notification within 24 hours of a confirmed security incident affecting Customer Data, including a description of the incident, the data types affected, containment steps taken, and recommended mitigation. Whether this same 24-hour commitment applies uniformly to self-serve customers without a signed agreement is not yet publicly documented.
Do you undergo third-party security audits or penetration testing?
Not yet — a formal penetration-testing program is on the roadmap, not in place today.