Enterprise

Compliance & Data Sovereignty

GCTRL is designed for regulated and enterprise environments where where your data lives and who touched it are first-class questions. Four pillars carry that posture: a complete audit trail, GDPR-aware session and personalization handling, EU AI Act transparency built into the product, and on-prem / local inference so nothing leaves your network.

Posture note: the design references below (ISO 27001-aware design, TISAX-readiness as a north star) describe GCTRL's engineering posture and intent. They are not a claim of formal certification or audit. Treat them as how the system is built to behave, not as a compliance attestation.


Audit Trail

Every access to the knowledge graph is logged - including every denied access. Each entry records:

FieldWhat it captures
Acting tokenWhich API token (and its owner) made the request
ActionRead, write, query, search, merge, etc.
ResourceThe entity, knowledge base, or graph touched
Clearance usedThe effective clearance applied to the request
OutcomeGRANTED or DENIED

Because denials are logged just as carefully as grants, the audit trail answers both "who saw this?" and "who tried to see this and was stopped?" - the second question is usually the one auditors care about.

The trail is queryable and filterable - by token, by action, by resource, by clearance, by outcome, and by time window - so you can reconstruct exactly what any token did, or surface every denied attempt against a sensitive compilation.

Filter examples
  outcome = DENIED  AND  resource.kb = "ACME Specs"     → every blocked attempt
  token   = partner-acme  AND  action = write           → everything a colleague wrote
  clearance >= CONFIDENTIAL  AND  action = read          → all sensitive reads

See Access Control & Multi-Tenancy for how clearance and grants generate the outcomes that land in this trail.


GDPR / DSGVO

GCTRL keeps personal and conversational data minimal by design, with explicit user control over anything that persists.

Incognito query mode

Incognito mode keeps a query session in browser memory only. The session and its context are never persisted server-side - close the tab and it is gone. This is the default posture for sensitive or ad-hoc questions where no record should remain.

Opt-in personalization profile

GCTRL can build a personalization profile to improve results over time, but:

  • It is opt-in - off until the user explicitly enables it.
  • It is built only from standard-mode history - incognito sessions never contribute to it, by construction.

Right to be forgotten

A user can erase their personalization profile at any time. Right-to-be-forgotten removes the profile and the standard-mode history it was derived from, returning the user to a clean state.

ModeStored server-side?Feeds personalization?
IncognitoNo - browser memory onlyNo
StandardYesOnly if personalization is opted in
Personalization profileYes, until erasedn/a - it is the profile

EU AI Act

GCTRL is an AI system placed on the EU market by Cinque Monti Ltd. as its provider. This section states, in plain language, where GCTRL sits under Regulation (EU) 2024/1689 (as amended by the 2026 digital omnibus) and what that means for you as a deployer.

Posture note, again: this is our good-faith self-assessment, not legal advice and not a conformity attestation. If you embed GCTRL in a context that is itself high-risk under Annex III, the high-risk obligations for that use sit with you as the deployer.

Where GCTRL sits

  • Not high-risk by intended purpose. GCTRL's intended purpose is knowledge extraction, fusion, retrieval and question answering over your own documents. That purpose does not fall under Annex III, and GCTRL implements no practice prohibited by Article 5.
  • Not a general-purpose AI model provider. GCTRL integrates third-party open-weight models that you choose and run on your own hardware (or cloud models you opt into). We do not train or provide the models themselves; the model providers carry the GPAI obligations.

Transparency (Article 50, applicable since 2 August 2026)

  • You always know you are talking to an AI. Talk to Graph is presented as an AI system, and the chat carries an explicit notice.
  • AI-generated content is marked. Auto-generated wiki pages, summaries and public graph embeds carry a machine-readable ai-generated marking, so downstream systems can recognise synthetic content.
  • Answers are verifiable, not just plausible. Every answer is grounded in the graph and traces back to its sources - the practical antidote to treating AI output as fact.

What GCTRL gives you for your own AI Act duties

Your duty as a deployerWhat GCTRL provides
Record-keeping and traceabilityThe forensic audit trail above: every access, every denial, queryable
Human oversightClearance ranks, scoped tokens, and source-traced answers a human can verify
Data governanceOn-prem deployment and local inference: the data lifecycle stays under your control
Transparency toward your usersAI notices and machine-readable content markings, out of the box
Accuracy monitoringPublished benchmarks and per-answer source receipts

On-Prem & Local Inference

GCTRL runs entirely on your own hardware. With local Ollama providing inference:

  • No data leaves your network. Prompts, documents, graph content, and answers all stay inside your perimeter.
  • Zero token cost. Local inference means no per-token billing and no external API dependency.
  • Full data sovereignty. You control the hardware, the storage volumes, and the model - there is no third party in the data path.

This is what makes the GDPR and audit posture credible end-to-end: it is not "we promise not to look," it is "the data physically never leaves." For self-hosting details and pointing GCTRL at native Ollama or your own model, see the Infrastructure settings and the FAQ / Troubleshooting page.


Built for Regulated Environments

GCTRL's design posture targets enterprise and regulated use:

  • ISO 27001-aware design - access control, audit logging, and least-privilege tokens are built in rather than bolted on.
  • TISAX-readiness as a north star - the architecture is shaped with industrial/automotive information-security expectations in mind.
  • Data sovereignty by default - on-prem deployment and local inference keep the entire data lifecycle inside your control.

Again: these describe how the system is engineered, not a formal certification. They are the design targets that explain why the audit trail, clearance model, and local-first architecture exist.


See also

  • Access Control & Multi-Tenancy - ownership, clearance ranks, grants, and KB-scoped tokens.
  • Benchmarks - including the ~0 ms cost of enforcing access control on every query.
  • FAQ / Troubleshooting - local Ollama, data locations, and what (never) goes to the cloud.