Why now – Palantir alternatives for Europe: what 'sovereign' actually means, and how European public bodies are decidingRegister →
Compliance

Compliant by architecture

Most platforms bolt compliance on at the end. Scrydon builds it in. Guardrails, policy-as-code authorisation, immutable audit logs, key control and document classification are part of the runtime — so the controls these frameworks demand are enforced as your AI and data actually run.

And because every control is observable, framework evidence packs map them back to the regulations, giving your risk, security and compliance teams something concrete to show.

Frameworks

Frameworks we support

Each page explains the framework in plain language and maps Scrydon's controls to its obligations. We align with and produce evidence for these frameworks; formal conformity for your own deployment remains your responsibility.

AI Act

EU AI Act

European Union

Providers, deployers, importers and distributors placing AI systems on the EU market or whose AI output is used in the EU.

GDPR

General Data Protection Regulation

European Union / EEA

Any organisation that processes the personal data of people in the EU/EEA, whether established in the Union or offering goods, services or monitoring from outside it.

DORA

Digital Operational Resilience Act

European Union

Financial entities across the EU — banks, insurers, investment firms, payment and crypto-asset providers and others — and the ICT third-party providers that serve them.

NIS2

NIS2 Directive

European Union

Essential and important entities across critical sectors — energy, transport, water, health, digital infrastructure, public administration, manufacturing and more — and their supply chains.

SecNumCloud

SecNumCloud

France (ANSSI)

Cloud service providers seeking French ANSSI qualification, and the public-sector and sensitive-data organisations that require qualified, sovereign cloud services.

ISO 27001

ISO/IEC 27001

International

Any organisation that operates an information security management system — routinely required of software vendors, service providers and regulated enterprises by customers, regulators and procurement.

ISO 42001

ISO/IEC 42001

International

Any organisation that develops, provides or uses AI systems and wants a certifiable management system for doing so responsibly — providers and deployers preparing for the EU AI Act in particular.

CRA

Cyber Resilience Act

European Union

Manufacturers, importers and distributors of products with digital elements — hardware and software — placed on the EU market, including software vendors and the organisations that build connected products on top of them.

Our own programme

We hold ourselves to the same standard

We ask customers to trust the controls we build, so we run our own compliance programme against the same yardsticks. Scrydon operates an information security management system aligned with ISO/IEC 27001 and an AI management system aligned with ISO/IEC 42001 — the first international standard for AI governance, and one very few vendors can point to.

We publish status, not promises. Certification claims will appear here only once external audits are complete — until then, this is exactly where the programme stands.

Policy framework: 40 policies approved and in force across the company.
Continuous control monitoring: Controls are monitored continuously in Vanta.
Internal audit: Underway.
External certification audits: The next milestone on the roadmap.