Trust Center

Trust enforced in the system. Not asserted in a document.

Security, compliance and sovereignty are structural properties of how the platform operates, not external checks applied after deployment. Governance cascades through every layer.

Four Principles of Trust

Your Data

Customer-sovereign deployment into your own cloud. No data leaves your environment. No shared tenancy. No inference data used for training. Full residency controls across jurisdictions.

Your Environment

Model-agnostic gateway routes across frontier and fine-tuned models. No single-vendor dependency. Every token, tool call, and cost event visible in real time.

Your Control

Kill-switch authority over any agent, workflow, or model in real time. Deterministic rollback. Governance cascades structurally. No tier can escalate its own permissions.

Your Jurisdiction

UK-founded. UK / EU-headquartered. Not subject to the US CLOUD Act. In sovereign and on-premise modes, data never transits Deliverance infrastructure.

Three Dimensions of Security

Security by AI

  • Threat detection
  • Anomaly monitoring
  • Access pattern analysis
  • Automated response

Security of AI

  • Prompt-injection defence
  • Data-poisoning protection
  • Memory isolation
  • Model-extraction defence

Security of Usage

  • PII redaction
  • Output filtering
  • Policy enforcement
  • Data-loss prevention

Regulatory posture

EU AI Act fines · up to €35M or 7% of global turnover

EU AI Act

Built for high-risk system requirements. Article 9-15 controls implementable as policy-as-code.

GDPR

Article 9 special-category handling. Data residency by deployment mode. DPIA support.

DORA / PRA / FCA

Operational-resilience controls for regulated financial firms. Audit lineage on demand.

NIS2

Critical-infrastructure controls and incident reporting workflows for telcos, energy, transport.

NHS DSPT

Aligned for clinical workloads on UK NHS infrastructure.

IEC 62443

Aware of OT/IT segmentation requirements for industrial deployments.

Compliance posture

ISO 27001 certified. Controls already encoded.

Where we've been independently audited, we say so. Where we're mid-cycle, we say so. Where it's on the roadmap, we say so. The platform doesn't wait for a logo to behave like a certified system.

Certified

ISO 27001

Information security management system

ISO 27001 certified

In active pursuit

ISO 42001

AI management system, first international standard for AI governance

Encoded in runtime

EU AI Act Art. 5 + 9-15

Prohibited practices + high-risk system controls enforced at inference

Adversarial defences

MITRE ATLAS

Prompt injection, data poisoning, model extraction encoded as runtime checks

DPIA-ready

GDPR Art. 35

Data Protection Impact Assessment templates and lineage on demand

On the roadmap

SOC 2 Type II

Security · Availability · Confidentiality trust services criteria

Need a deeper trust review?

For DPAs, security questionnaires, or regulator-specific posture documents, contact our team directly. We respond fastest to enquiries that name the regulator and deployment mode.

The agentic enterprise

Your agents are already running. The only question is who's in control.