---
title: "AI Security and Data Sovereignty | YPAI"
url: https://ypai.ai/ai-security/
description: "Norwegian AS on EEA infrastructure, with per-recording provenance and an evidence package a procurement review can read. Transfer controls set per project."
source: "src/copy/routes (route /ai-security/)"
---

# Norwegian jurisdiction. Reviewable evidence.

> Norwegian AS on EEA infrastructure, with per-recording provenance and an evidence package a procurement review can read. Transfer controls set per project.

YPAI is a Norwegian company with no US corporate entity, operating EEA infrastructure. Data residency, subprocessors and international-transfer controls are defined per project. SCCs are available for any customer-directed transfer outside the EEA.

Access · logged in the EEA

## Seven artefacts a procurement review can read.

Produced on request and scoped to the engagement. Each one answers a question your reviewers will ask.

Where each recording came from and who handled it, recorded per file.

One consent per contributor, per purpose, with the timestamp and the wording they agreed to.

The dialect, region and speaker balance of the dataset, reported as aggregates.

The quality gates the dataset passed, with the logs and metrics behind each one.

A hash per version and a change log between versions, so a delivered set can be matched to the one you tested.

The register of infrastructure and service providers behind the engagement, available on formal request.

How the data was selected and stratified, written so a reviewer can repeat the draw.

## Six regulations, one control and one artefact each.

The regulation your review names, the control YPAI operates for it and the artefact that proves the control ran.

GDPR Article 7 (Lawful basis: consent)

Consent per contributor and purpose, with a withdrawal workflow

Consent records generated per data subject

GDPR Article 12 to 23 (Data subject rights)

A data-subject-rights workflow that writes its own audit trail

GDPR Article 28 (Data processor terms)

Article 28 DPA terms in every engagement contract

EU AI Act Article 10 (Data governance for high-risk AI)

Provenance per recording and documented sampling against bias

Provenance logs and sampling methodology documentation

MiFID II (Financial services voice and recording)

Five-year recording retention built into the architecture

System provenance and cryptographic retention metadata

HIPAA (Limited to consent language and contract review)

Healthcare consent wording and a contract review scoped to the project

Per-contributor signed consent paired with documented data-handling terms

## Single jurisdiction. By design.

YPAI is a Norwegian company with no US corporate entity. Data residency, subprocessors and international-transfer controls are defined per project. SCCs are available for any customer-directed transfer outside the EEA.

## What YPAI signs and what YPAI operates.

Two lists. The commitments YPAI signs in every engagement, and the controls YPAI operates whether or not a contract asks for them. Both are standing artefacts, so a security team can assess fit from standard documents before a call.

The Data Processing Agreement comes with every engagement, ready for countersignature.

Hard deletion within 30 days of contract end, written into the master service agreement.

Standard Contractual Clauses for customer-directed transfers outside the EEA.

Each record is timestamped and bound to the processing purpose, in an immutable audit trail.

Access, rectification and erasure requests run through one workflow that logs each step.

Each engineering control is mapped to the Article 32 requirement it satisfies.

GDPR Article 33 window, with the audit trail entry timestamped from the moment of awareness.

Norwegian AS operating EEA infrastructure by default, under Norwegian jurisdiction.

EU AI Act Article 10 alignment

Controls mapped to EU AI Act Article 10 data governance requirements.

The seven artefacts above, produced for the engagement on formal request.

## What procurement asks before signing.

Where does YPAI store customer data?

In the European Economic Area by default, on Norwegian and EEA infrastructure providers. A transfer you direct outside the EEA runs under Standard Contractual Clauses.

What is the data erasure SLA?

Hard deletion within 30 days of contract end, written into the master service agreement, with the audit trail preserved. Erasure requests from data subjects run through the DSR workflow, which logs each step.

How are healthcare-specific legal and data-handling requirements handled?

Healthcare-specific legal roles, data flows, residency, and contract terms are assessed before scope acceptance and confirmed in signed project documentation.

Documented and available on formal request as part of the procurement workflow. The sub-processor register is one of the seven artefacts in the evidence package.

Can you sign our DPA, or do we use yours?

Either. YPAI's DPA covers the GDPR Article 28 terms and comes ready for countersignature. Your DPA is accepted with redlining where the engagement scope allows it.

What is your breach notification window?

In line with GDPR Article 33: 72 hours from awareness, with the audit trail entry timestamped from the same moment.

What compliance evidence does YPAI provide for security review?

A documented evidence package with every engagement: GDPR Article 28 DPA ready for countersignature, per-contributor consent records, DSR workflow documentation, a 30-day erasure SLA in the master service agreement, SCCs for customer-directed transfers outside the EEA, and EU AI Act Article 10 alignment. The commitments and controls panel above lists each artefact. The <a href="/platform/">platform walkthrough</a> shows how a session produces this record, from specification through verified delivery.

## Get the artefacts your procurement committee will ask for.

A named YPAI engineer replies inside one EU business day with the sovereignty assessment, the draft DPA and the evidence package scoped to your workload.
