Skip to content
FortiqAI Technologies LLP
Compliance & Regulatory Fit

AI That Fits Inside the Obligations You Already Have.

FortiqAI is not a compliance product. It is AI infrastructure designed so that using it does not create a new compliance problem. This page sets out how a private deployment maps to the regimes our customers work under, so your DPO, QA head, or compliance officer can assess it directly.

01

India: DPDP Act, 2023

Processing that never leaves your control.

Under DPDP, an organisation remains accountable for personal data it holds, including when a processor handles it — and every additional third party in the chain is an additional surface to govern, notify, and audit.

A FortiqAI deployment removes that chain. Documents are processed inside infrastructure you already control, under access rules you already set, with an audit log you already own. There is no transfer, no external processor for the AI layer, and no cross-border question to answer.

02

Pharma: GxP and CSV

Documentation to support your qualification, not claims about it.

We do not sell a "Part 11 certified" system, because that certification does not exist to be sold — qualification is performed by you, in your environment. What we provide is the installation, configuration, and change documentation to support your CSV process, plus the audit trail, access control, and traceability characteristics your protocols will test for. We work to your qualification templates, not ours.

03

BFSI: RBI and SEBI Expectations

Data stays in your environment, and every query is accounted for.

Regulated financial institutions face expectations around data localisation, outsourcing governance, and the auditability of automated processing. An on-premise deployment addresses the first directly. The query audit log addresses the third: you can answer "who asked the system what, and on which records" without depending on a vendor.

04

GDPR and HIPAA-Aligned Environments

Architecture that supports the obligations.

Data minimisation, purpose limitation, access control, and the ability to demonstrate processing activity are all served by a deployment where the data never moves. We are precise about the boundary: the architecture supports these obligations; the compliance conclusion is yours to reach with your own counsel.

05

What We Don't Claim

Where our certifications currently stand.

FortiqAI does not currently hold SOC 2 or ISO 27001 certification. We say so plainly rather than implying otherwise, and we will tell you where that stands when you ask. What we will do is walk your security team through the deployment architecture in detail and answer their questionnaire directly.

Security Architecture

Request the Security Architecture Overview.

A direct walkthrough of the deployment architecture with your security or compliance team.

Request Overview
On your infrastructure · Air-gap capable · Role-based access · Every answer cited · Full audit log