Reliable data for your AI. Responsible AI to enable your business.
Every score shows its working. A qualified human signs it off.
Rated itself 3.81 out of 5. The records support 2.45.
The record of processing was rated level 4. Nothing was produced to show it exists, so the rating caps at 2. — Art 30 · Art 5(2)
A retention schedule was described but not shown, and nothing triggers disposal when a period ends. — Art 5(1)(e) · Art 5(2)
The one area that produced records — provider reports, patch summaries, access reviews. Above target, and the report says so. — Art 32 · Art 5(1)(f)
Requests were described as managed. There is no log, no response times and nothing to check the claim against. — Arts 12–22
Two pillars. One handshake.
AI is only as good as the data behind it. We ready both.
Sentinel Data
Data your AI can rely on — lawful, protected, provable.
UK & EU GDPR, security, transfers — scored control by control.
Rights in practice: requests, breaches, records, training.
Mapped to the ICO frameworks · UK & EU GDPR
Sentinel AI
AI your business can trust — visible, controlled, provable.
Every AI tool known, assessed, controlled and watched — under a policy you can enforce.
Strategy, data, people, process — ready to adopt AI that pays back.
Mapped to ISO/IEC 42001 · NIST AI RMF · EU AI Act
Sentinel Align — a third pillar, in reserve: data quality, cataloguing, ownership. Built when you need it.
Three organisations. Six verdicts.
Both pillars, same engine. The scoring tells them apart.
Professional services
32 staff · nothing written down
97 findings. Outsourced IT was the only thing holding.
Financial services
140 staff · confident it was covered
94 claims capped. Confidence fell to 60% and 59%.
Research & education
600 staff · everything evidenced
18 findings between them. The gap was AI, not data.
Completed assessments. Every figure is engine output. Organisations are synthetic and never named.
Different pillars. The same honest method.
Are you doing it?
Conformance with the regulator or standard, control by control.
How well, how consistently?
Maturity from 1 to 5 — the scale below.
One to five. Three is the line.
Below it, you can describe your controls. At it, you can prove them. The same scale covers data protection and AI.
Unsupported
Held up by whoever happens to be there.
Asserted
You say it happens. Nothing shows it.
Evidenced
Written down, followed, provable.
Measured
You check it works, and act on what you find.
Sustained
It improves itself.
Saying it isn't evidencing it.
One organisation rated itself level 3 or higher ninety-nine times. It could evidence twenty-one.
- 1The client answers: level 4 — managed.
- 2The engine asks for the evidence. None recorded.
- 3The rating is held at level 2, and the report says why.
Records of Processing Activities
- Rating
- Level 2 (held from 4 — nothing evidenced)
- Target
- Level 4 · gap of 2 · high severity
- Risk
- Inherent 3×5 → residual 2×5 · high
- Maps to
- UK GDPR Art 30
Without a current record of processing the organisation cannot say what it processes or why — a direct Art 30 breach, and the first document an ICO audit asks for.
Four documents. One free call to start.
Posture report
Where you stand, with confidence on every score.
Remediation roadmap
What to fix first — people, process, technology.
Risk register
The risk behind each gap, and who owns it.
Evidence pack
Audit-ready, officer-signed, working shown.
See where you stand.
A free 30-minute scoping call: your data, your AI use, and what a first assessment looks like.
hello@conduit488.com