Updated March 2026

AI Trust & Compliance

SolaraIMPACT is built on a foundation of security, transparency, and responsible AI β€” so your team can focus on the work.

πŸ›‘οΈ

SOC 2 Type II Certified

Security, Availability & Confidentiality. Audited by Accorp Partners CPA LLC. No Exceptions Noted.

βš–οΈ

EU AI Act Compliant

Limited Risk classification. Full Article 50 transparency obligations applied.

πŸ”

GDPR Ready

Data Processing Agreement available. Sub-processor transparency. Data subject rights supported.

βœ•

Zero AI Training

We never train AI models on your data. Neither do our model providers via our API configurations.

EU AI Act Compliance

SolaraIMPACT is classified as a Limited Risk AI system under Regulation (EU) 2024/1689 (the EU AI Act). This means:

  • Not a high-risk AI system

    SolaraIMPACT is not used for employment decisions, biometric identification, credit scoring, law enforcement, or any other high-risk category.

  • Full Article 50 transparency

    All AI-generated content is clearly labeled as AI-generated within the platform.

  • Formal Risk Assessment complete

    We have completed a formal Risk Classification & Compliance Assessment, available to enterprise customers on request.

  • Comprehensive documentation

    We maintain a comprehensive EU AI Act compliance documentation set including Risk Classification Assessment, AI System Technical Description, Human Oversight Policy, Post-Market Monitoring Plan, and AI Incident Response Procedure.

Classification: Limited Risk

SolaraIMPACT meets the transparency and documentation requirements under Article 50 of the EU AI Act.

All compliance documentation is available for direct download in the Documents section below.

AI Transparency

SolaraIMPACT is an AI-powered platform. We are transparent about exactly how AI works in our product:

What AI does in SolaraIMPACT

  • Analyzes your inputs (briefs, objectives, market context) and generates strategic recommendations, content, and analyses
  • Powers 21+ specialized modules for marketing and PR workflows
  • Produces advisory outputs that your team reviews, edits, and uses β€” never autonomous actions

What AI does NOT do

  • Make decisions without your review β€” all outputs require human approval before any external use
  • Train on your data β€” we use zero-data-retention API configurations with all model providers
  • Store your prompts with model providers β€” your data stays within our Azure infrastructure

AI Models We Use

Provider Model Use Cases Trust & Security
Anthropic Claude Strategic analysis, content generation, workflow planning trust.anthropic.com
Google Gemini Search-integrated research, competitive intelligence cloud.google.com/security
OpenAI GPT Specialized analysis, alternative perspectives trust.openai.com
xAI Grok Real-time web search, news and social intelligence x.ai/security

Security

SOC 2 Type II Certified. Infrastructure on Microsoft Azure. Here's how we protect your data:

Encryption

TLS 1.2+ in transit, AES-256 at rest across all data stores (Cosmos DB, file storage, Redis).

Access Control

Role-based access, user-level data isolation, MFA via Clerk (SAML 2.0, OIDC, OAuth 2.0).

Infrastructure

100% Microsoft Azure. Inherits Azure's SOC 1/2/3, ISO 27001, FedRAMP High certifications.

Monitoring

24/7 Azure monitoring, application health checks, 99.5% uptime target, incident response SLA.

Your Data

You own it. We protect it. We never misuse it.

Data Ownership

You retain full ownership of all inputs and AI-generated outputs. We claim no rights over your content.

Data Residency

Hosted on Microsoft Azure East US 2. EU data residency available on request for customers with specific requirements.

Data Deletion

30-day retrieval window after subscription ends. Delete specific jobs or all your data at any time on request.

Certifications & Standards

Standard SolaraIMPACT Azure Anthropic OpenAI Google
SOC 2 Type II βœ“ βœ“ βœ“ βœ“ βœ“
ISO 27001 Via Azure βœ“ βœ“ βœ“ βœ“
ISO 42001 (AI) Via Anthropic/Google β€” βœ“ β€” βœ“
FedRAMP Via Azure βœ“ (High) β€” β€” βœ“ (High)
GDPR βœ“ (DPA available) βœ“ βœ“ βœ“ βœ“
EU AI Act βœ“ (Limited Risk) β€” βœ“ βœ“ βœ“
No API Training βœ“ β€” βœ“ βœ“ βœ“

Compliance Documentation

All compliance documents are publicly available for immediate download. No request needed.

πŸ“„
Data Processing Agreement (DPA)

GDPR-compliant DPA including Standard Contractual Clauses for EU-US data transfers. Sign and return to privacy@solaracloud.ai.

↓ Download PDF
πŸ”
Privacy Policy

How we collect, use, store, and protect your data. Covers data subject rights, retention, and international transfers.

↓ Download PDF
βš–οΈ
AI Transparency Policy (Article 50)

Our EU AI Act Article 50 obligations: how AI-generated content is disclosed to users within the platform.

↓ Download PDF
πŸ”—
Sub-Processor List

Complete list of sub-processors including AI model providers (Anthropic, OpenAI, Google, xAI), infrastructure, authentication, and payments.

↓ Download PDF
πŸ“‹
EU AI Act Risk Classification Assessment

Formal classification of SolaraIMPACT as a Limited Risk AI system under Regulation (EU) 2024/1689, with full compliance rationale.

↓ Download PDF
πŸ–₯️
AI System Technical Description (System Card)

Architecture overview, LLM integrations, data flows, safety measures, and known limitations of the SolaraIMPACT AI system.

↓ Download PDF
πŸ‘οΈ
Human Oversight Policy

How SolaraIMPACT ensures human review and control over all AI outputs before any external use or action.

↓ Download PDF
πŸ“Š
Post-Market Monitoring Plan

Ongoing AI performance tracking, incident thresholds, review cadence, and continuous improvement procedures.

↓ Download PDF
🚨
AI Incident Response Procedure

Incident classification, escalation paths, and regulatory reporting procedures for AI-related events.

↓ Download PDF
πŸ—„οΈ
Data Governance & Input Data Policy

Input data handling, retention schedules, bias mitigation controls, and data quality standards.

↓ Download PDF

SOC 2 Type II Report is available under NDA β€” contact us to request access.

Questions?

We're here to help with any security and compliance inquiries.

Security & Compliance

privacy@solaracloud.ai

General Questions

contact@solaracloud.ai

Response Times

We respond to compliance inquiries within 48 hours and provide substantive responses within 5 business days.