AI for resilience,
in absolute compliance.
Discover how our "Policy-as-Code" architecture respects and anticipates the requirements of the EU AI Act and global AI frameworks.
Our Founding Doctrine
Because we evaluate human decision-making under stress, our system falls into the "High-Risk" categories (HR/Employment) of the EU AI Act. Here are our 4 pillars of absolute compliance.
Zero Data Retention (ZDR)
LLM models are not used to store data. Any conversation ("Hot Data") is purged from RAM the millisecond the mathematical score is calculated. No history is kept.
No Model Training
We guarantee contractually and technically (via isolated Enterprise APIs) that no data entered by your employees will be used to retrain public or private AI models.
Human-In-The-Loop (HITL)
AI does not have the final say. Our "Audit Corridor" identifies scores in an uncertainty zone (e.g., 60-80%). These files are sequestered so a sworn human auditor can validate the compliance.
Determinism (Policy-as-Code)
The "AI Judge" does not perform psychological profiling. It operates at 0.0 temperature and simply applies a normative matrix grid (Your security rules) strictly to the extracted verbatims.
Dual-Core Architecture
Structural separation of powers to prevent any "punitive hallucination".
The AI Coach (Interaction)
Fluid and empathetic model. Its sole mission is to conduct the Socratic investigation. It never scores the user.
The AI Judge (Measurement)
Cold analytical model isolated from context. It reads an anonymized transcript, looks for Behavioral Indicators (ICO), and delivers a mathematical verdict.
Global Legal Alignment
Our enclave architecture (Dual-Core) allows us to comply with regulations on every continent without modifying the source code.
EU AI Act (Europe)
Strict compliance with transparency (Art. 13), data governance, and human oversight (Art. 14) requirements for High-Risk employment-related systems.
AI Bill of Rights (USA)
Adherence to the principles of "Notice and Explanation" and "Human Alternatives" (Right to appeal via our Audit Corridor).
AIDA (Canada)
Alignment with the Artificial Intelligence and Data Act (AIDA) requiring discriminatory bias mitigation and strict logging (WORM).
What we do with your data
This page describes processing for Predictive CyberLab and Predictive CyberScore. It is readable without an account. Contractual choices (who is controller, conversation retention) live in Settings and in the contract.
Who is accountable for the data
The law requires a “controller”: the organisation that decides why data is used and how.
In practice it is usually the account that opens the campaign and pays for seats (for example an industrial group). If a supplier runs its own campaign, it is the supplier. The contract may also name OCF, or a shared regime. That choice is not hardcoded: it is written per contract.
Why we process this data
- Predictive CyberLab — film, sequences, exam and awareness certificate. We record who watched, who answered, and who earned the certificate.
- Predictive CyberScore — assessment modules and organisation score. We measure performance (HVS) and failure rate (HFR), not an automated HR sanction.
- Supply-chain steering — aggregated boards for the network head (completion, risk). A supplier’s employee names are not visible to the network head.
What data
Work identity (first name, last name, email, organisation, language), learning progress, exam answers, certificate date. On the honor board: first name and initial only, and only if the person opted in.
No ID documents, no payment data in these journeys, no resale to third parties.
Retention and AI conversations
Zero Data Retention (ZDR): when the organisation option is on, coach conversations are not stored after the session. They are not used to retrain a model.
Exam results and the certificate remain for the life of the contract: they prove the campaign was completed.
Role of AI and human oversight
Two distinct systems. The coach explains and helps: it does not decide hiring or discipline. The judge computes a score and compares it to a threshold set by the organisation.
After two exam failures, the next decision is human: the client organisation, or a partner it appoints. No single automated decision about a person.
Who can see what
- The company administrator sees participants of their campaign.
- The network head sees aggregated indicators on suppliers, not their named lists.
- OCF uses this data only to operate the platform. No resale.
Audit our Technology
Our white papers, compliance matrices, and security attestations (SecNumCloud) are available to CIOs and DPOs.
Contact Compliance Team