Trust through system-specific evidence

Trust the exact operating path—not a blanket claim.

For every delivered system, Compsia defines the data, users, providers, actions, controls, tests, fallback, evidence and operating limits. Where proof is incomplete, the path is narrowed or validated before production.

Evidence standard dated 2026-07-19Page updated 2026-08-24

Production is a release decision.
Not a marketing adjective.

Compsia designs, launches and operates custom AI production systems. For each system, we define the exact data, sources, actions, owners, controls, acceptance tests and operating limits.

Production transition occurs only when the agreed tests pass or the customer explicitly accepts documented residual limitations. Human review is one possible control; it does not waive privacy, access, retention, incident or confidentiality requirements.

Boundary

Name the complete data path.

Purpose, categories, source authority, identities, retrieval, model and connector providers, copies, logs, retention, export and deletion.

Authority

Enforce exact action rights.

Permitted, approval-gated and prohibited actions; authenticated approvers; account scope; confidence behaviour and escalation.

Operation

Keep change attributable.

Versioned releases, incidents, provider and model changes, support ownership, operating measures, rollback and manual continuity.

Two gates before recurring, action-capable production.

These gates describe Compsia's delivery standard. The customer-specific release record must still prove which controls exist for the exact implementation.

Gate ABefore real customer data

Authorize the data path.

Accurate controller/processor and provider records; named categories, authority and retention; scoped accounts; passed access tests; no unapproved writes; incident ownership; and tested export and deletion.

Gate BBefore recurring actions

Authorize the action path.

Gate A plus default-deny side effects, exact allowlists, structured material decisions, attributable approval, replay-safe execution, retrieval scope, production-like failures, fallback and an accurate trust pack.

What we will say—and what we will not infer.

Claims are attached to the relevant system version, configuration, controls, tests and operating evidence. The public site deliberately avoids converting an implementation pattern into a universal product guarantee.

Human approval

Exact actions only

We name the actions and enforcement. We do not imply that every action across a platform is globally approval-gated.

Data location

Actual provider path

We name regions and transfers only when the exact provider route proves them. We do not claim that data always stays in source systems.

Evidence

Operational history

We use “audit trail” only if the exact evidence supports that term. Otherwise we describe run, approval and change records precisely.

Compliance

No blanket status

No public GDPR, EU AI Act, SOC 2, ISO 27001, penetration-test or independent-audit claim is made without current, scoped evidence.

Performance

No guarantees

We do not guarantee ROI, perfect accuracy, zero incidents or safety. Baselines, tests, limitations and accepted outcomes carry the claim.

Skybridge

Included, bounded access

Skybridge access is included without an additional platform licence fee within contracted users, usage, capabilities, duration and support limits.

Procurement receives the facts for the real system.

A production proposal should provide the relevant legal entity and contracting authority; architecture and data flow; providers, regions and transfers; security and access controls; retention, export and deletion; incident and breach process; continuity, recovery and credential ownership; support and escalation; held insurance or certifications; and explicitly unavailable controls.

The customer remains responsible for lawful processing, source authorization, business decisions, commercial commitments and its own security, privacy and procurement approvals.