Compliance reports
A compliance report is a single document that shows how the platform handled your AI over a period of time: how much of your inference stayed on EU-resident models, where anything was routed outside the EU and under what safeguards, and how the PII firewall protected personal data along the way. It is built from the platform's own records and frozen as a PDF, so you can hand it to an auditor, a data protection officer, or your own compliance team as evidence.
You will find it under Platform > Compliance.
What a report covers
Each report is for a period you choose, a single month or a quarter. It brings together, for that period:
- Residency. How many requests ran on EU-resident models, and what share of your total that was. This is the headline most reviewers ask for.
- External transfers. Any requests routed to a non-EU model, tied to the acknowledgment your organization recorded, along with the number of attempts the egress guard blocked.
- Personal data protected. The categories of personal data the PII firewall detected and pseudonymized, by type and count. The report never contains the personal data itself, only how much of each kind was seen and protected.
- Governance events. Guard activity and any compliance-mode changes in the period.
- Processing footprint. The models, providers and regions that served your requests, with request and token totals.
Generating a report
On the Compliance page, choose a period, a month or a quarter, and select Generate report. Generation runs in the background, and the finished report appears in the list below when it is ready, usually within a moment.
You can generate a report for the same period more than once. Each run produces a new, self-contained document rather than changing an earlier one, so your history stays intact.
What the report is for
The report turns "we keep your data in the EU" from a claim into something you can show. Because it is generated from the platform's append-only records and frozen with a checksum, it stands on its own as a record of what actually happened, not a promise about what should happen. Typical uses are handing it to an external auditor, attaching it to a data protection impact assessment, or keeping a standing archive for your own governance.
Downloading and keeping reports
Every report you generate is listed on the page with its period and the date it was generated. Select the download button to get the PDF.
Reports are immutable once generated. The platform stores each one exactly as it was produced and never edits it, so a report you generated months ago remains valid evidence for that period even after the underlying activity has aged out of the live logs.
Automatic monthly reports
You do not have to remember to generate a report. At the start of each month the platform automatically generates and freezes the previous month's report for you, so you always have a standing archive to draw on. Generating one yourself is for when you want a specific period, such as a full quarter, on demand.
Who can generate reports
Compliance reports are available on the Team plan and above. Within your organization, owners and admins can generate reports, and every member can view and download the reports that exist.
Good to know
The report never contains your request data. Like the audit log, a compliance report records details about your activity, the counts, categories and outcomes, never your prompts, the models' responses, or the personal data inside them. It is safe to share with an auditor or a colleague.
It reflects a point in time. A report captures the period you chose from the records available when it was generated. Because reports are frozen, the way to keep long-term evidence is to let the monthly reports accumulate, or generate the periods you care about as you go.
Compliance documents (Enterprise)
Beyond the residency and audit report, the platform generates two pre-filled legal documents from a saved compliance profile:
- GDPR Article 30 record (ROPA). The record of processing activities for your AI processing on the platform: controller and processor identity, purposes and legal basis, categories of data subjects and personal data, recipients and sub-processors, third-country transfers and safeguards, retention, and security measures.
- EU AI Act deployer record. A structured record of your use of general-purpose AI through the platform: the models and regions used, the intended purpose, human oversight and data governance measures, and international transfers.
You provide the legal facts once (legal entity, DPO contact, processing purposes and legal basis, categories of data subject) in the compliance profile. The platform fills in the rest automatically from your records: the personal data categories detected by the PII firewall, the models and regions you used, the external transfers that actually occurred, your sub-processors, and the retention window on your plan.
Each document is a pre-filled draft for your Data Protection Officer to review and adopt. It is not legal advice. Your organization remains the data controller, and the platform is the processor providing the tooling.