Our methodology
A trust profile is only useful if the method behind it is public. This page explains how evidence is collected, how confidence is scored, how often it is re-checked and what is deliberately not published.
Evidence, not attestation
Each control is backed by records created in the platform: registered systems with named owners, logged training, a published policy with signature records, vendor assessments. A control is only marked verified when the underlying records exist.
Confidence levels
Every control carries a confidence level derived from the completeness and freshness of its evidence, the sources used and the date it was last checked. Confidence, sources and last-checked date are published alongside the status.
Recheck cadence
Controls expire. Each has a recheck cadence, and a profile shows when a control was last confirmed rather than implying permanent compliance.
What is never published
Public profiles carry aggregate evidence only. No personal data, no employee names, no document contents, no risk-register detail. A firm can verify its position without exposing its internal record.
Machine-readable
The same data is available as JSON at the public verification endpoint so procurement systems and AI agents can read a profile directly.
Limits
Applicability depends on the AI system and how you use it. EUQA helps you document and evidence your position; it is not legal advice. EUQA verifies that governance evidence exists and is current. It does not certify that a given AI system is lawful in a given use case.