Trust

Security, transparency and regulatory rigour, in one place.

Trust is not declared: it is documented. This page brings together the three pieces with which Alethexis sustains it — how we protect your organisation's information, which controls you can review for yourself, and the criteria with which we read the regulation we apply.

When they ask, you do not draft an answer. You open it.

The day the question arrives — from a client, from an insurer, from an auditor, from the board — this is what you show:

  • Your AI systems inventory, complete and up to date.
  • The risk classification of each system, with its legal basis.
  • The evidence: what was done, who did it and when, document by document.

Not a report from eight months ago. Your situation today, traceable back to its origin.

Security

Data residency in the European Union, isolation between customers with Row Level Security, encryption in transit and at rest, and an immutable activity log. All ten measures, explained plainly.

See the security measures

Trust Center

Our own public Trust Center, generated with the same platform our customers use. Documented, reviewable controls, each with a date, an owner and evidence.

158 documented, reviewable controls in the catalogue · live count on 28 August 2026.

See the Trust Center

Regulatory approach

Every obligation the platform presents carries its regulatory nature in plain sight: what is law in force, what is a legal obligation with a confirmed future date, and what is best practice. Without inflating obligations.

Read our approach

We do not just say it. You can audit it. Documented, reviewable controls in our Trust Center, with a date, an owner and evidence.

See the Trust Center →

Alethexis demos use fictitious organisations and data. Our customers' data is handled with the same rigour we help you document: it is never marketing material.

Our regulatory approach

Alethexis works on the binding framework in the EU: Regulation (EU) 2024/1689 (EU AI Act), as amended by Regulation (EU) 2026/1744, Regulation (EU) 2016/679 (GDPR) and the national data protection law that implements it in each Member State. Every legal reference in the platform is verifiable against the official text published on EUR-Lex.

Every obligation the platform shows you carries its regulatory nature in plain sight, with a four-level taxonomy:

  • LM

    Legally Mandatory. Legal obligation in force for your specific case.

  • LC

    Legally Conditional. Legal obligation with a confirmed future date: it applies from the date of application shown in the platform.

  • BP

    Best Practice. International best practice (ISO, NIST, OECD) — never a direct legal obligation.

  • IM

    Internal Methodological. Alethexis’s own methodological control, with no direct basis in law.

That distinction is deliberate: we do not inflate obligations to sell urgency, nor present international best practice as if it were law. What is required appears as required; what is advisable, as advisable.

Alethexis documents and organises your compliance work; it is not legal advice and does not replace the roles the regulation requires of your organisation. Ultimate conformity is each customer’s responsibility.