AI ACT READY

Security, privacy and trust

Operational controls you can examine.

A factual overview of the controls, data boundaries and assurance evidence supporting the controlled AI Act Ready SaaS environment.

Review draft — not approved for publication. This page is deliberately excluded from search indexing and public navigation while its wording is reviewed.

Current operating boundary

AI Act Ready is operating a controlled UK business-to-business £0 beta boundary. Live card collection, positive pricing, automatic paid conversion, metered usage and live billing are disabled. Product demonstrations and verification activity use synthetic data; no customer data was used for the current demo or security-verification evidence.

Security controls

Access and tenant boundaries

Organisation and project checks enforce tenant isolation. Administrator, Consultant and Customer permissions are enforced server-side. Administrators and consultants use mandatory multi-factor authentication.

Evidence handling

Restricted evidence uploads use an allow-list, size and signature validation, opaque private storage and owner checks. Unscanned files are explicitly labelled and are not represented as trusted or malware-scanned.

Audit and monitoring

Material security and business actions are recorded in an append-only, hash-chained audit trail. Structured health monitoring and application logs support incident investigation and operational response.

Recovery

Encrypted recovery archives are retained in Amazon S3 in the London region and protected using AWS KMS. Backup integrity and an isolated restoration rehearsal have been verified.

Security assurance

The current candidate passed AI Act Ready's internal security-verification gate on 26 August 2026. The gate included secret scanning, dependency review, Semgrep static analysis, Trivy source, configuration and rebuilt-image scanning, 40 security tests, tenant and role negative tests, OWASP ZAP active and DOM-XSS testing, production build verification and CycloneDX software-bill-of-materials generation.

No Critical or High finding remained. Four bounded Medium residual risks are owned: session inactivity timeout, comprehensive authorization-denial audit events, authenticated ZAP automation and migration of six bounded inline style attributes. This is internal verification, not an independent penetration test, certification or guarantee of security.

Privacy and AI-provider controls

Data use

Customer evidence must not be used to train external AI models. Any future use of real, customer, confidential or sensitive data with an AI provider requires a fresh data-flow and privacy review.

Current AI settings

HubSpot generative AI, CRM-data access, conversation-data access, files access, Breeze Assistant and AI model training are disabled. The historical Nexos/OpenClaw capability is stopped and requires review before reactivation.

Service providers

The approved provider register identifies the contracting entities, purposes, processing locations, transfer safeguards and current operational status of providers used for hosting, recovery, CRM, scheduling and subscription administration.

Data rights

The privacy notice explains the information collected, purposes and lawful bases, international transfers, retention, individual rights and the route for questions or requests.

Retention and account exit

Routine enquiries and prospect records are reviewed and deleted or anonymised when no longer needed. For the controlled SaaS lifecycle, documented controls provide a maximum 30-day read-only/export period followed by working-data deletion within 90 days, subject to an applicable legal hold. Minimised contractual, audit and accounting records may be retained for the legally required period, including up to six calendar years where applicable.

Documents and contact

For privacy, security or provider questions, contact info@aiactready.co.uk. AI Act Ready is a trading name of Immersible Ltd, company number 11084336.