Review draft — not approved for publication. This page is deliberately excluded from search indexing and public navigation while its wording is reviewed.
Current operating boundary
AI Act Ready is operating a controlled UK business-to-business £0 beta boundary. Live card collection, positive pricing, automatic paid conversion, metered usage and live billing are disabled. Product demonstrations and verification activity use synthetic data; no customer data was used for the current demo or security-verification evidence.
Security controls
Access and tenant boundaries
Organisation and project checks enforce tenant isolation. Administrator, Consultant and Customer permissions are enforced server-side. Administrators and consultants use mandatory multi-factor authentication.
Evidence handling
Restricted evidence uploads use an allow-list, size and signature validation, opaque private storage and owner checks. Unscanned files are explicitly labelled and are not represented as trusted or malware-scanned.
Audit and monitoring
Material security and business actions are recorded in an append-only, hash-chained audit trail. Structured health monitoring and application logs support incident investigation and operational response.
Recovery
Encrypted recovery archives are retained in Amazon S3 in the London region and protected using AWS KMS. Backup integrity and an isolated restoration rehearsal have been verified.
Security assurance
The current candidate passed AI Act Ready's internal security-verification gate on 26 August 2026. The gate included secret scanning, dependency review, Semgrep static analysis, Trivy source, configuration and rebuilt-image scanning, 40 security tests, tenant and role negative tests, OWASP ZAP active and DOM-XSS testing, production build verification and CycloneDX software-bill-of-materials generation.
No Critical or High finding remained. Four bounded Medium residual risks are owned: session inactivity timeout, comprehensive authorization-denial audit events, authenticated ZAP automation and migration of six bounded inline style attributes. This is internal verification, not an independent penetration test, certification or guarantee of security.
Privacy and AI-provider controls
Data use
Customer evidence must not be used to train external AI models. Any future use of real, customer, confidential or sensitive data with an AI provider requires a fresh data-flow and privacy review.
Current AI settings
HubSpot generative AI, CRM-data access, conversation-data access, files access, Breeze Assistant and AI model training are disabled. The historical Nexos/OpenClaw capability is stopped and requires review before reactivation.
Service providers
The approved provider register identifies the contracting entities, purposes, processing locations, transfer safeguards and current operational status of providers used for hosting, recovery, CRM, scheduling and subscription administration.
Data rights
The privacy notice explains the information collected, purposes and lawful bases, international transfers, retention, individual rights and the route for questions or requests.
Retention and account exit
Routine enquiries and prospect records are reviewed and deleted or anonymised when no longer needed. For the controlled SaaS lifecycle, documented controls provide a maximum 30-day read-only/export period followed by working-data deletion within 90 days, subject to an applicable legal hold. Minimised contractual, audit and accounting records may be retained for the legally required period, including up to six calendar years where applicable.
Documents and contact
For privacy, security or provider questions, contact info@aiactready.co.uk. AI Act Ready is a trading name of Immersible Ltd, company number 11084336.