Skip to content
GroundSetTrust Center

Built to survive your review.

Deployment, data handling, certification status and the regulatory atlas — the page to forward to your CISO, your risk committee and your auditor.
01Deployment & data handling

Nothing leaves the perimeter.

01Deployment
In-VPC or fully air-gapped. GroundSet runs in your environment, not ours.
02Inference
No external calls. Models, rules and ledger execute inside your perimeter.
03Processing
Ephemeral. Documents are handled in-memory and purged on completion.
04Retention
Zero, by architecture rather than policy. Decision records stay in your environment, under your retention rules.
05Review
Full InfoSec review passed at a BSP-regulated, Tier-1 digital bank.
02Certifications

Funded workstreams, stated as such.

We publish what is in progress; milestone dates are shared under NDA. Silence would read as absence.

SOC 2 Type I

In progress

SOC 2 Type II

In progress

ISO/IEC 27001

In progress

VAPT attestation

Live workstream
03Regulatory atlas

What each regime asks of AI decisioning — and how GroundSet is designed to support it.

01Philippines · Bangko Sentral ng Pilipinas

BSP IT Risk Management

What it requires of AI decisioning

  • A board-approved IT risk management framework covering systems that support credit and operational decisions.
  • Oversight of third-party and outsourced technology, including where customer data is processed.
  • Information security controls, access management and audit trails for critical systems.

How GroundSet is designed to support it

  • Runs inside the bank's own VPC — no customer data is processed on vendor infrastructure.
  • Every decision is recorded with its evidence, rule version, outcome and any human override.
  • Rules are versioned objects the bank's own governance approves; the ledger shows which version decided what.
02Singapore · Infocomm Media Development Authority

IMDA Model AI Governance Framework for Agentic AI (Jan 2026)

MAS FEAT principles (fairness, ethics, accountability, transparency) inform the same design.

What it requires of AI decisioning

  • Verifiable identity and accountability for every agent action.
  • An audit trail of who acted, under whose authorisation, on what basis.
  • Human oversight at defined checkpoints, proportionate to risk.

How GroundSet is designed to support it

  • Each decision is attributed to a rule version and the policy owner who authorised it.
  • Escalations route to named human roles; their overrides are set in the same record.
  • Any decision can be replayed end-to-end for a supervisor or auditor.
03India · Digital Personal Data Protection Act, 2023

India DPDP

What it requires of AI decisioning

  • Processing of personal data only for a specified, lawful purpose.
  • Reasonable security safeguards and breach notification.
  • Erasure once the purpose is served, and accountability for processors.

How GroundSet is designed to support it

  • Processing stays inside the data fiduciary's environment; GroundSet does not receive the data.
  • Documents are handled in-memory and purged — zero retention by architecture.
  • Decision records stay inside your perimeter, under your retention policy.
04United States · Federal Reserve, OCC, FDIC

SR 26-2

What it requires of AI decisioning

  • Board-level governance of AI decisioning that sits outside model-risk guidance.
  • Documented, reviewable decision processes and ongoing monitoring.

How GroundSet is designed to support it

  • Deterministic rules: the same input produces the same output, so behaviour is testable before and after change.
  • An immutable ledger of every judgement gives the board and examiners the record the guidance expects.
05European Union · Regulation (EU) 2024/1689

EU AI Act

What it requires of AI decisioning

  • For high-risk uses such as creditworthiness and insurance risk assessment: automatic logging of system events.
  • Transparency to deployers, and effective human oversight.
  • Accuracy, robustness and a documented risk-management system.

How GroundSet is designed to support it

  • Logging is the product: evidence, rule version, outcome and override are recorded for every decision.
  • Human review is a first-class route, with the reviewer and their reasoning set in the record.
  • Deterministic policy execution makes each outcome explainable against the rule that produced it.

GroundSet is designed to support compliance with the frameworks above. Compliance is determined by each institution and its supervisor; nothing on this page is legal advice.

04Responsible disclosure

Found something? Tell us first.

Report vulnerabilities to security@groundset.tech. We acknowledge within one business day.

05Data Processing Agreement

Available on request.

Our DPA and the security annex are shared with institutions in evaluation. Ask for them with your walkthrough.

Walkthrough with security annex
06Next step

See one real workflow become infrastructure.

We map one decision workflow from your operation and show it running end-to-end — understood, decided, routed, and set in the ledger. Thirty minutes, your data patterns, no slideware.

Or the decision infrastructure required.