Compliance & Trust

We claim nothing that is not on a register.

Trust pages are usually badge walls. Ours is a rule: every claim on this page is either a registrable fact you can verify, an operating practice we will demonstrate under NDA, or an explicitly labelled roadmap item. As certifications land, their certificate numbers appear here — and not before.

Operating posture

Data residency

Client data is processed and stored on infrastructure PureTensor Ltd owns and operates in the United Kingdom. Geographic backup replication goes to our disaster-recovery site in Iceland — inside the UK-adequacy family of jurisdictions, never to US-controlled infrastructure.

Jurisdiction

Your contract is with a company registered in England and Wales; the hardware your workloads run on is physically in the UK and legally operated by that company. Where your AI runs is a legal decision — ours is stated as registrable fact, not marketing.

Isolation

Each client environment is isolated at the infrastructure layer. Fine-tuning and retrieval run inside your isolation boundary; your data never leaves it and is never used for any other client or any model we offer to others.

Encryption & access

Encryption at rest and in transit. Least-privilege access, with named engineers — you know who can touch your environment. Full audit logging of every inference request.

Deletion

Documented deletion procedures on request, covering primary storage, replicas, and backups, with written confirmation of completion.

Vulnerability disclosure

We operate a public vulnerability disclosure programme and respond to good-faith reports. See the VDP page for scope and safe-harbour terms.

Certification roadmap

UK GDPR / Data Protection Act 2018
In force
Operating posture: privacy policy, data-subject-rights process, and records of processing are published on this site.
Cyber Essentials
Roadmap
The UK government-backed baseline. First certification milestone on our roadmap.
Cyber Essentials Plus
Roadmap
Independently audited tier; expected to follow Cyber Essentials.
NHS Data Security & Protection Toolkit
Roadmap
For health-sector work; assessed annually against the NHS framework.
ISO/IEC 27001
Roadmap
Full information-security management system certification; the long pole on the roadmap.

Your regulatory duties, our architecture

Law firms and chambers. The Law Society's generative-AI guidance asks solicitors to retain direct control and oversight over the tools that touch client material. A dedicated, UK-operated environment — where you know the operator, the location, and the audit trail — is that control, delivered as architecture.

FCA-regulated firms. AI supporting important business functions is material outsourcing. We support your outsourcing register, resilience mapping, and audit requirements with named-operator accountability and full request logging — and since July 2026 the UK supervises the largest cloud providers as critical third parties, a concern a dedicated UK operator does not carry into your register.

Healthcare organisations. Clinical data demands demonstrable control over processing. Our environments keep clinical workloads on UK-resident, isolated infrastructure; DSPT assessment is on our certification roadmap above, and we will complete it before taking NHS-connected work.

Related: Privacy Policy · Data Subject Rights · Vulnerability Disclosure · AI Transparency · Legal Notice