Skip to content
Empley

Trust · Governance

Data residency, audit trail, kill switch, version lock.

In short: your data stays in Europe, every run is logged, anything can be stopped instantly, and every version can be restored. Below are the documents your security lead and DPO want before a call.

Sunlight falling through ferns on a forest floor.
A way forward even when visibility is low. Clear rules are the direction.

Principles

Three promises we'll put in writing.

01

You own everything

Code, prompts, configuration, logs. We hand it over turnkey.

02

No shadow operations

The agent runs where you already have security, backup and incident response.

03

Reversible

A kill switch. A rollback. No lock-in to our platform, because there is none.

Data residency

We deploy where your security already lives.

Your environment, your rules

Data never leaves your house.

The agent runs in the cloud tenant you have already security-reviewed. We install, you own it. We never see production data.

  • Deployment via your existing IaC pipeline.
  • Keys and secrets stay in your vault.
  • Logs and traces are written to your observability system.

We deploy where you already are

  • Microsoft Azure

    Sweden Central · West Europe · North Europe

  • AWS

    eu-north-1 (Stockholm) · eu-west-1 (Dublin)

  • Google Cloud

    europe-north1 · europe-west4

  • Privat OpenShift

    On-prem datacenter · Sovereign cloud

Have a different environment? We adapt to you, not the other way around.

Heavy wooden doors with brass ring handles.

Direction, not red tape

Rules that show the way forward.

You don't get more rules to manage. You get a direction to follow, with the documents your security lead and DPO actually ask for.

Direction before regulation. Proof before claims.

Order that can be audited.
Dark green leaves in low light.
Someone always answers for the decisions

Governance pack

One document, versioned, ungated.

Principles, regulation mapping, phases and the gatekeeper contact, all in one PDF. Updated with version history.

Current version

Empley_Governance_Pack_v1.pdf

Last updated 2026-05-01. No sign-up required.

VERIFIED
Open the pack

Gatekeeper on our side

Governance lead

Named contact at kick-off, with a direct number.

info@empley.com·Reply within 24 hours on weekdays.

Always includedGovernance packMonthly impact reportYou own the data and the modelsPause at any point

How an engagement runs

Five phases, ten weeks, one named gatekeeper.

  1. Fas 01

    Kick-off

    Week 1

    Kick-off with your security lead and DPO. We map data flows, responsibilities and regulation. You get a named gatekeeper with a phone number.

    Ansvarig: Governance lead on our side

  2. Fas 02

    Blueprint

    Weeks 2–3

    Deterministic agent blueprint before code. INPUT, STEPS, OUTPUT, GUARDRAILS. You see the shape first, on paper.

  3. Fas 03

    Pilot

    Weeks 4–6

    Runs on real data in your sandbox. Full audit trail. No production, no decision goes live.

  4. Fas 04

    Production

    Weeks 7–9

    Rolled out with a kill switch, on-call and version lock. We stay close until you're confident running it.

  5. Fas 05

    Handover

    Week 10

    You own the code, prompts and data. We stay on as support at your pace. No platform lock-in.

Audit trail

Every run is traceable, signed, exportable.

An actual excerpt from a run log. This is production, not a brochure.

audit.log · policy-compliance-agent · 2026-06-12read-only
  1. 2026-06-12 09:14:22policy-agent@nordicrun.startCase #A-24817, source: HRISa4f9…c21b
  2. 2026-06-12 09:14:24policy-agent@nordicpolicy.matchPolicy clause 4.2 applied, exception 7.1 not relevantb1d0…8e77
  3. 2026-06-12 09:14:27policy-agent@nordicdraft.outputDraft to HR partner for review, 3 sources attached9c22…41af
  4. 2026-06-12 09:22:03anna.lind@nordiskhuman.reviewApproved by HR partner, one wording adjusted77e5…102d
  5. 2026-06-12 09:22:11policy-agent@nordicrun.completeSent to client via email, archived in the case file3f88…b640

EU AI Act and other regulation

How we map to what you already follow.

No new compliance to own. We fit into what you already have and deliver what your auditor wants to see.

  • Data-residensGDPR, Schrems IIThe agent runs in your cloud tenant, in any EU region you already use.
  • Identity and accessISO 27001 A.9Your existing IdP via OIDC or SAML. Role-based access. No shadow accounts.
  • Audit trailISO 27001 A.12.4Full run log per agent, exportable and signed. Stored on your side.
  • Keys and secretsNIS2, DORAModel provider keys live in your vault. We never see them.
  • Version controlChange managementEach agent is locked to a version in production. Upgrades are decisions, not surprises.
  • Kill switchDORA, operativ resiliensOne button shuts the agent down instantly. No support ticket, no waiting.
  • Personal dataGDPR art. 28Data processing agreement, clear responsibilities, and deletion on request from day one.
Next step

Want a walkthrough with your security lead? We'll book 30 minutes, you set the agenda.

See all packages

The same rules apply across all eight packages.

See the agent roster

Which agents do the work, and what each one can touch.