Trust is not declared: it is documented. This page brings together the three pieces with which Alethexis sustains it — how we protect your organisation's information, which controls you can review for yourself, and the criteria with which we read the regulation we apply.
The day the question arrives — from a client, from an insurer, from an auditor, from the board — this is what you show:
Not a report from eight months ago. Your situation today, traceable back to its origin.
Data residency in the European Union, isolation between customers with Row Level Security, encryption in transit and at rest, and an immutable activity log. All ten measures, explained plainly.
See the security measuresOur own public Trust Center, generated with the same platform our customers use. Documented, reviewable controls, each with a date, an owner and evidence.
158 documented, reviewable controls in the catalogue · live count on 28 August 2026.
See the Trust CenterEvery obligation the platform presents carries its regulatory nature in plain sight: what is law in force, what is a legal obligation with a confirmed future date, and what is best practice. Without inflating obligations.
Read our approachWe do not just say it. You can audit it. Documented, reviewable controls in our Trust Center, with a date, an owner and evidence.
See the Trust Center →Alethexis demos use fictitious organisations and data. Our customers' data is handled with the same rigour we help you document: it is never marketing material.
Alethexis works on the binding framework in the EU: Regulation (EU) 2024/1689 (EU AI Act), as amended by Regulation (EU) 2026/1744, Regulation (EU) 2016/679 (GDPR) and the national data protection law that implements it in each Member State. Every legal reference in the platform is verifiable against the official text published on EUR-Lex.
Every obligation the platform shows you carries its regulatory nature in plain sight, with a four-level taxonomy:
Legally Mandatory. Legal obligation in force for your specific case.
Legally Conditional. Legal obligation with a confirmed future date: it applies from the date of application shown in the platform.
Best Practice. International best practice (ISO, NIST, OECD) — never a direct legal obligation.
Internal Methodological. Alethexis’s own methodological control, with no direct basis in law.
That distinction is deliberate: we do not inflate obligations to sell urgency, nor present international best practice as if it were law. What is required appears as required; what is advisable, as advisable.
Alethexis documents and organises your compliance work; it is not legal advice and does not replace the roles the regulation requires of your organisation. Ultimate conformity is each customer’s responsibility.