The four documents banking procurement and DPO teams ask for in week one of a vendor review. Each one is publicly accessible, versioned, and printable. Where a question requires confidential mechanism detail, the public document signposts to our NDA-gated security briefing — that boundary is intentional.
EU AI Act Article 13 — purpose, capabilities, limitations, human oversight, lifetime, performance metrics. The first artefact a deployer's AI-governance team will ask for.
UK GDPR Article 28 — controller / processor obligations, sub-processors, transfer mechanisms, return / deletion, audit rights. Ready to counter-sign.
Every third party that processes personal data on our behalf — purpose, region, transfer mechanism, replacement notice. Re-published when anything changes.
UK GDPR Article 35 + EU AI Act Article 27 — pre-filled Data Protection Impact Assessment template the deploying customer can adapt. Mapped to ICO guidance.
For our SOC 2 Type I readiness statement, pen-test summary, region map, or signed SCC / UK IDTA — request our full trust pack from trust@vault-hire.com. Replies typically within 1 working day.