A useful system has to be governable.

Sources, criteria, responsibility, controls and limits are not added after the model. They are part of the capability being built.

Where do you want to start?

The 38 Trust Layer is a methodology in formalisation: it helps make data, criteria, responsibilities, controls and dependencies legible. It is not a certified standard or a certification.

AI security lifecycle diagram, from discovery through governance.

Legible governance

Who can decide, verify and stop the system.

Acceptance criteria, human oversight, known limits and ownership make a capability discussable before it becomes opaque.

The partner retains domain decisions. Roles, escalation thresholds and responsibility boundaries are defined for the individual engagement.

Practices already in use

Acceptance criteria written before development and, where relevant to a specific engagement, source traceability, human validation and an audit trail.

Controls defined per project

Deployment, segregation, retention, integrations, logging, backup, recovery and compliance requirements depend on risk, existing systems and contractual responsibility.

Sovereign by choice

Sovereignty means deliberately choosing models, hosting, data location, access and dependencies. It does not mean “everything on-premise” or “Europe only” by definition.

What we do not claim

We make no certification claim. We do not promise zero error, absolute security, universal SLAs or one architecture for every partner. Failure modes and responsibility boundaries must remain legible.

Constraints change the architecture.

Bring security, procurement, data and sovereignty into the first conversation.

Talk to us
Contact · Let’s talk