๐Ÿ›ก๏ธ Compliance & Trust

AAMOS Trust & Certifications

Verified compliance posture, independent audits, and regulatory readiness across all AAMOS modules and the Ouroboros Enterprise OS platform.

16
Modules Assessed
92%
ISO 27001 Coverage
6
Frameworks Active
4
Compliant
4
In Progress
1
Planned
๐Ÿ‡ช๐Ÿ‡บ
Regulatory Compliance
EU AI Act ยท GDPR ยท Primal Charter
๐Ÿค–
EU AI Act Classification
European Parliament Regulation (EU) 2024/1689
Compliant 16 modules classified

All 16 AAMOS modules have been classified under the EU AI Act risk framework. 15 modules fall under Limited Risk classification (Art. 52 transparency obligations met). The People module (HR/performance management) is classified as High Risk (Annex III, point 4) with full compliance measures implemented including human oversight, data governance, and bias testing.

Finance โ€” Limited
Commerce โ€” Limited
CRM โ€” Limited
Marketing โ€” Limited
Governance โ€” Limited
Ledger โ€” Limited
KYC โ€” Limited
Payroll โ€” Limited
Notifications โ€” Limited
Dynasty โ€” Limited
Scaffold โ€” Limited
Analytics โ€” Limited
Connect โ€” Limited
Academy โ€” Limited
Operations โ€” Limited
People โ€” High Risk
๐Ÿ”’
GDPR Compliance
Regulation (EU) 2016/679 โ€” Data Protection
Compliant Art. 5โ€“7, 17, 22, 25, 30, 33, 35

Full GDPR compliance implemented across all data processing activities. Record of Processing Activities (ROPA) is complete and current. Data Protection Impact Assessments (DPIA) conducted for all high-risk processing. Consent management, right to erasure (Art. 17), and automated decision-making safeguards (Art. 22) are fully implemented.

GDPR Article Coverage94%
View GDPR documentation โ†—
๐Ÿ“œ
Primal Charter v1.0.0
Wavult Group โ€” Constitutional AI Governance
Compliant All agents bound

All AAMOS AI agents operate under the Primal Charter v1.0.0 โ€” a constitutional AI governance framework governing agent behaviour, escalation protocols, red lines, and human oversight requirements. The Charter is ratified through the Constitutional Court mechanism and enforced at the Hermes routing layer.

View Primal Charter โ†—
๐Ÿ“‹
ISO Standards
ISO 27001 ยท ISO 9001
๐Ÿ”
ISO 27001:2022 โ€” Information Security
International Organization for Standardization
In Progress 92% conformity

ISMS (Information Security Management System) established and operational. Internal audit completed with 92% conformity to Annex A controls (93 controls total). Gap assessment identifies 7 controls requiring additional evidence before formal certification audit. Target certification: Q3 2026.

Annex A Controls Implemented86 / 93
View ISO dashboard โ†—
โœ…
ISO 9001:2015 โ€” Quality Management
International Organization for Standardization
In Progress 88% conformity

Quality Management System (QMS) implemented covering software development, deployment, and service delivery processes. Customer satisfaction monitoring, non-conformance management, and continuous improvement processes are active. Clause 8 (Operations) and Clause 9 (Performance Evaluation) are fully implemented. Target certification: Q4 2026.

QMS Clause Coverage88%
๐Ÿ…
Independent Audits
TรœV AI Safety ยท SOC 2 Type II
๐Ÿ”ฌ
TรœV AI Safety Readiness
TรœV Rheinland โ€” AI System Audit 2026
Compliant Audit 2026-04-27

Independent AI safety readiness assessment conducted by TรœV Rheinland on 2026-04-27. The audit evaluated model robustness, explainability, bias detection, human oversight mechanisms, and incident response procedures. AAMOS achieved Readiness Level 3 โ€” the highest tier for enterprise AI deployments.

AI Safety Score94 / 100
View TรœV report โ†—
๐Ÿ”‘
SOC 2 Type II Preparation
AICPA Trust Services Criteria
In Progress Pre-audit phase

SOC 2 Type II preparation underway covering the five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Internal readiness assessment complete. Audit window scheduled for Q3 2026 (90-day observation period). Security and Availability criteria are already at audit-ready maturity.

Criteria ReadinessSecurity ยท Availability ยท Confidentiality
๐Ÿ›ก๏ธ
Security Posture
Penetration Testing ยท Vulnerability Management
๐Ÿ”ด
Penetration Testing & Red Team
Internal Red Team ยท External Assessment
Compliant Last: 2026-05-04

Comprehensive red team exercise completed 2026-05-04. Attack surface assessment covered API endpoints, authentication flows, data exfiltration vectors, and social engineering scenarios. Zero critical vulnerabilities found. 3 medium-severity findings remediated within 48 hours. Next scheduled assessment: Q3 2026.

View red team report โ†—

Certification Status Notice
Compliance statuses reflect the current internal assessment and third-party audit results as of May 2026. Formal ISO certifications are in progress and expected Q3โ€“Q4 2026. All documented controls are operationally active. For enterprise due diligence inquiries, contact compliance@wavult.com.