artifact 01 of 07
Per-recording provenance
Documentation of data lineage detailing the origin and chain of custody for individual project recordings.
Requested via Request a sample evidence package
AI data, evaluation and implementation under one accountable delivery model.
Contact us Become a ContributorTrust and data sovereignty
YPAI is a Norwegian entity operating European infrastructure. It is not a US-domiciled provider under the CLOUD Act, by corporate structure. SCCs support transfers outside the EEA.
Seven artifacts produced on request, validated by procurement teams across regulated mid-market and enterprise buyers.
artifact 01 of 07
Documentation of data lineage detailing the origin and chain of custody for individual project recordings.
Requested via Request a sample evidence package
artifact 02 of 07
Contributor agreements validating specific permissions scoped by individual and intended processing purpose.
Requested via Request a sample evidence package
artifact 03 of 07
Aggregated distribution reports validating the balance of dialect and regional representations across the dataset.
Requested via Request a sample evidence package
artifact 04 of 07
Validation logs and metric reports detailing the quality assurance gates passed during dataset compilation.
Requested via Request a sample evidence package
artifact 05 of 07
Immutable cryptographic hashes and change logs tracking modifications across dataset iterations.
Requested via Request a sample evidence package
artifact 06 of 07
A documented register of third-party infrastructure and service providers, available upon formal request.
Requested via Request a sample evidence package
artifact 07 of 07
Technical documentation defining the statistical approach used to select and stratify data for model training.
Requested via Request a sample evidence package
Six regulations, with the YPAI control mechanism and the evidence artifact that proves it.
Rows appear only where YPAI holds a control and an evidence artifact.
YPAI is a Norwegian entity operating European infrastructure. It is not a US-domiciled provider under the CLOUD Act, by corporate structure, not by contract. SCCs are available for any customer-directed transfer outside the EEA.
YPAI procurement value is anchored in structural EEA jurisdiction and GDPR-native engineering. The contractual commitments and operational controls below are standing artifacts, so security teams can assess architectural fit without commissioning custom documentation.
Frequently asked
In the European Economic Area (EEA) by default. Norwegian and EEA infrastructure providers only. Customer-directed transfers outside the EEA are supported via Standard Contractual Clauses (SCCs).
30 days from a verified erasure request, with audit trail preserved. Hard deletion is written into the master service agreement.
Healthcare-specific legal roles, data flows, residency, and contract terms are assessed before scope acceptance and confirmed in signed project documentation.
Documented and available upon formal request as part of the procurement workflow. Sub-processor transparency is one of the 7 audit artifacts shipped per project.
YPAI ships a standardized DPA covering GDPR Article 28 terms. Customer DPAs are accepted with redlining where the engagement scope makes it operationally feasible.
In line with GDPR Article 33: 72 hours from awareness, with the audit trail entry timestamped from the same moment.
A documented evidence package with every engagement: GDPR Article 28 DPA ready for countersignature, per-contributor consent records, DSR workflow documentation, a 30-day erasure SLA in the master service agreement, SCCs for customer-directed transfers outside the EEA, and EU AI Act Article 10 alignment. The Commitments and Controls panel above lists each artifact.
A named YPAI engineer replies within one EU business day with the sovereignty assessment, draft DPA, and the evidence package scoped to your workload.