Skip to content
Spekir
← Back to Trust Center

COMPLIANCE

Our compliance posture

Where we stand on GDPR, the EU AI Act, and SOC 2 — without overstatement.

GDPR

Operational

We operate as a data processor under GDPR. Lawful basis: art. 6(1)(b) (contract) and art. 6(1)(f) (legitimate interest for security). DPIA readiness: template prepared for customers; we provide data flows and categories on request.

EU AI Act

Roadmap

Atlas supports Annex III risk classification and Article 6/9 compliance pack export. We track Article 13 (transparency) and Article 14 (human oversight) in the AI registry. Full coverage rolling out alongside the AI Act phased timeline (2026-2027).

SOC 2 Type 1

Planned

Evidence collection is scaffolded and controls are being implemented. Audit window planned 2027 H1. We are not currently certified.

ISO 27001

Not planned

Not planned at this stage. We will revisit when customer requirements and business scale make it the right investment.

We never display badges for certifications we do not hold. Status updates live on this page.