Skip to content

Compliance

This page describes Venturi’s compliance posture honestly: which controls are in-architecture today, and which formal attestations and programs are on a clearly-labeled forward roadmap. We never imply Venturi holds an attestation it does not yet hold.

How to read this page

The security architecture, tenant isolation, encryption, retention, erasure, and audit controls described elsewhere in this section are in-architecture and stated in the present tense. The formal compliance program below (SOC 2 attestation, the formal GDPR program, and EU AI Act registration) is a forward roadmap with explicit phase gates. The two are kept structurally distinct on this page.

SOC 2

SOC 2 status

SOC 2 Type I readiness/report is a target on our security roadmap, with Type II targeted within 12 months. It is not yet held.

Venturi never states or implies that it currently holds, or is certified for, SOC 2.

Item Roadmap position
SOC 2 Type I In progress, built on the audit-trail subsystem. (Type I attests control design at a point in time.)
SOC 2 Type II Targeted within 12 months of Type I; the Type II observation window starts immediately. (Type II attests operating effectiveness over a 3–12-month observation period.)
In-scope Trust Services Criteria Security (Common Criteria, mandatory), Availability, Confidentiality, and Processing Integrity. Processing Integrity is mandatory because the product produces the numbers customers bill on; it is the home of the confidence-cap, abstention, and chargeback-eligibility controls. Privacy is added when the first EU/regulated deal enters the pipeline.
Annual penetration test Tied to the SOC 2 program; critical findings are remediated before deployment.

The control foundation for the attestation is already in place: the immutable, append-only audit trail and the policy-event writer provide the tamper-evident control history that a SOC 2 examiner relies on. See the audit trail.

GDPR

Processor framing

Venturi acts as a data processor; your organization is the controller. Venturi processes personal data only on your documented instructions and commits the GDPR Article 28 processor obligations, including the Art. 28(3) DPA terms and the Art. 28(2) subprocessor change-notification and objection workflow. See Data-subject rights for how requests are fulfilled.

In-architecture today

  • Data minimization: content inspection is disabled by default, so Venturi processes invocation metadata, not prompt or completion content (GDPR Art. 5(1)(c)). See Data privacy & retention.
  • Cohort-only adoption intelligence (minimum cohort of 5, sub-cohort suppression, anti-differencing, and no individual-level view): the privacy core of the product.
  • Crypto-shred erasure within a 30-day SLA, with a deletion certificate, reconciled with the append-only architecture.
  • Pseudonymized audit trail retained under a named legal-claims / legitimate-interest basis.

GDPR data residency

Per-tenant data lives in a dedicated tenant data plane: your cloud account in self-hosted mode, or a Venturi-operated single-tenant environment in SaaS mode. The residency lane is fixed during onboarding; applicable transfers use Chapter V safeguards. See Residency and subprocessors.

Onboarding privacy artifacts

Item Onboarding status
Formal DPA (Art. 28(3) terms; SCCs where Chapter V applies) Included in the onboarding diligence pack
Record of Processing Activities (RoPA, Art. 30) Maintained for in-VPC metadata processing and cross-tenant aggregation
DPIA template (Art. 35) and works-council pack Included in the onboarding diligence pack for customer adaptation
Lawful-basis mapping (per processing activity) Included in the onboarding diligence pack
inference_geo customer-facing residency-control surface Post-onboarding roadmap; current deployments use the contracted residency lane

CCPA

For consumers and businesses subject to CCPA/CPRA, Venturi operates as a service provider: it processes personal information only to provide the attribution service on your instruction, does not sell or share personal information, and processes only the metadata required for attribution. Access, deletion, and portability requests are fulfilled through the same mechanisms described in Data-subject rights, including the crypto-shred deletion path. The same data-minimization posture (no content capture, cohort-only adoption intelligence) limits the personal-information footprint by design.

EU AI Act

The EU AI Act has two faces for Venturi: Venturi’s own provider self-classification, and EU-AI-Act compliance automation as a future product capability.

Self-classification: non-high-risk

Venturi documents a non-high-risk posture for its adoption-intelligence / attribution system. Venturi never asserts “low risk” generically. The posture rests on the EU AI Act Art. 6(3) conditions:

  • Primary condition (Art. 6(3)(c)): the system performs a narrow procedural task (detecting decision-making patterns or deviations from prior patterns) without replacing or influencing a human assessment; it surfaces aggregate, cohort-level signals for human review.
  • Fallback condition (Art. 6(3)(d)): the system performs a preparatory task to an assessment.
  • Registration assessment. Before placing an applicable system on the EU market or putting it into service, Venturi documents the classification and completes any registration required by Article 49. This page does not claim a registration obligation or completed registration where the statutory trigger does not apply.

Cohort-only design is the precondition

The classification depends on the actual deployment and use. Venturi keeps adoption intelligence cohort-only with a minimum cohort of 5 and no individual-level view. It additionally performs no emotion recognition or behavioral-state inference about individual workers.

The provider-versus-deployer roles and applicable transparency duties are documented, and a works-council pack is included in the onboarding diligence pack. The customer adapts the pack to its jurisdiction and workforce process.

Precautionary post-market controls

Even under the non-high-risk posture, Venturi adopts the EU AI Act post-market and serious-incident workflows as precautionary controls:

  • A post-market monitoring plan (Art. 72) that reuses the platform’s live calibration and drift monitors, the false-high-confidence and calibration-error gates, and the anomaly-detection system.
  • An AI incident runbook covering AI-specific failure modes (mass mis-attribution, a calibration/drift breach (which triggers automatic fallback to the heuristic baseline), confidence inflation, and evidence poisoning) with detection, rollback, customer-notification, and post-incident-review steps.
  • The Art. 73 serious-incident reporting workflow, recorded in the RoPA, so the channel exists if a classification ever changes.

Compliance automation (product capability)

EU-AI-Act compliance automation for your organization, an audit trail and frameworks mapped to attributed AI usage, is a roadmap product capability. The attribution graph is the natural substrate for “which AI system, used by whom, for what.” The audit trail ships today; automated compliance reporting is a later roadmap phase.

Control framework crosswalk

Venturi maintains a crosswalk mapping its in-architecture controls to the principal governance frameworks: NIST AI RMF, NIST SP 800-53 / CSF, ISO/IEC 27001 and 42001, and CISA Secure by Design. ISO 27001 (Information Security Management System) and ISO 42001 (AI Management System) certification are roadmap items; the mapping is provided now to accelerate diligence. The full crosswalk is on the Trust center.

Incident response & breach notification

A documented incident-response plan defines a Sev-1/2/3 severity taxonomy, escalation tiers, a post-incident-review requirement, and response targets. As processor, Venturi notifies you without undue delay (target ≤24 hours of becoming aware) so you can meet your GDPR Article 33 deadline. Operational incidents appear on the tenant-isolated in-product status surface with the next update time and a written post-incident summary for material incidents. The operational and breach-notification paths run in parallel where both apply.