AI Governance Framework
Who is accountable for AI, how a use case moves from idea to operation, how risk is classified and which tools are approved.
EU AI Act hooks
- Art. 4 AI literacy
- Art. 26 deployer obligations
- Art. 9 risk management
Opsio Vault AI is a secure gateway between your applications and the AI models. It runs in the EU, removes personal data before the model sees it, blocks passwords and keys, and logs every call for your auditor. Opsio's AI team operates it under a data processing agreement. For development teams building AI into products, and IT teams giving staff approved AI tools.
We show you the Vault AI portal, a real call being pseudonymised, a pasted secret being refused before any model sees it, and the evidence pack your auditor, customer or regulator can review. Then we agree the privacy profile that fits your organisation.

30 minutes with an Opsio AI & compliance specialist. See the portal, a live refused call and the evidence pack.
Public AI services are the fastest way for personal data to leave your organisation unrecorded. Blocking them doesn't stop it — it just removes the controls.
And they should. It is the biggest productivity gain in a decade — for writing, analysis, code, contracts and customer service.
Customer names, identity numbers, contract terms, source code — or a password pasted by mistake — all sent to a public AI service.
Under the GDPR your organisation remains accountable for that data as controller, whatever the AI vendor's terms say.
When an auditor, a customer or a regulator asks what went where, most companies can't answer.
Ban AI and staff move to personal accounts. The data leaves anyway — with no controls at all.
Hover a card to see exactly what each control does. Opsio runs, patches, monitors and answers for the platform under a data processing agreement.
The platform runs in AWS Frankfurt and calls models only through EU inference profiles or in Frankfurt itself.
Detected personal data is replaced with pseudonymous tokens before the prompt reaches the model.
Opsio keeps no copy of your prompts or answers, and Bedrock model-invocation logging is switched off.
A prompt containing a credential is refused before any model call — and costs nothing.
A versioned guardrail blocks jailbreaks, prompt injection and harmful content.
A write-once audit record for every request — metadata only, never the content.
Your applications and teams get leading large language models through one secure API and one portal. The privacy controls are enforced by the platform itself instead of promised in a policy — and Opsio runs, patches, monitors and answers for it.




The platform, the model catalogue and the guardrails are operated by Opsio — nothing to host yourself.
Updates, new models and guardrail versions are rolled out and tested by Opsio.
Availability, refusals, spend and anomalies are watched continuously.
Under a data processing agreement — Opsio is your processor, contractually bound.
Choose a company to see its models and what they cost today. Prices load from the live Vault AI price list, so what you see is what you're billed.
Choosing? Read our ChatGPT vs Claude comparison.
Keys, usage, cost, compliance evidence and invoices — for your developers, your DPO and your finance team. Shown from the real portal for a demo company.

Screens from the real Vault AI portal for a demo company. All figures are simulated.
Spend by model, by application and day by day, with cost alerts.
The price list you're on and what every model costs.
Download your records, or ask for a recurring report.
Your agreements, the terms that apply and who is involved.
Invite colleagues as Member (read) or Administrator.
Raise requests with Opsio and see live service status.
Escalation contacts, network allow-list and spend ceiling.
Four steps to get going, then your apps and tools call Vault AI exactly the way they call Anthropic or Amazon Bedrock today.
Sign the data processing agreement and agree your privacy profile: which data classes are allowed, your model catalogue and your limits.
Eight recorded onboarding checks — agreements, contacts, data and transfer questionnaire, technical set-up, first key — ending in a dated onboarding certificate.
Issue a key per application in the portal. Point your app at the Vault AI endpoint from your approved network addresses or over VPN.
Follow usage and cost, see every refused call explained, set budgets, and download the evidence pack for your auditor.
Vault AI speaks the Anthropic Messages API and the Amazon Bedrock Converse API. Existing applications, Anthropic SDKs and AWS SDKs keep working — you change a base URL and a key.
Keep your apps and SDKs. Change a base URL and a key; use model aliases like claude-sonnet. Streaming requests are supported — the answer is released once it has passed outbound inspection.
Tools that let you set a custom Anthropic or Bedrock endpoint work the same way, each with its own key. Model names sent by common tools are mapped to your approved EU models.
The portal: issue and revoke keys, set budgets and limits, see usage and cost per model, every refused call explained, invoices, and the evidence pack for your auditor.
import os, anthropic
client = anthropic.Anthropic(
base_url="https://vault.opsiocloud.com",
api_key=os.environ["VAULT_AI_KEY"], # opsio_… key for this app
)
reply = client.messages.create(
model="claude-sonnet", # alias from your catalogue
max_tokens=1024,
messages=[{"role": "user", "content": "Summarise this contract…"}],
)
print(reply.content[0].text)
Refusals come back as clear error codes, and the portal shows which policy acted and what to change. The most common ones:
A password, key or token was in the prompt. No model was called and nothing was charged.
Remove the secret and send again.
The model isn't in your catalogue — including any non-EU model route.
Use one of your approved aliases.
A requests-per-minute or daily token limit was reached.
Retry after the stated time, or raise the limit.
A spend ceiling or application budget set to hard-stop was reached.
Raise the budget in the portal.
The guardrail couldn't be applied, so the call was refused rather than served unchecked.
Retry — this is the fail-safe working.
Your people use the best AI models on your own data. The models run in the EU, personal data is pseudonymised before it reaches the model, a pasted password is stopped at the door, and when your auditor asks, you can show exactly what happened.
How Vault AI's controls map to the regulations your auditors, customers and regulators ask about.
Vault AI enforces the technical controls. The policies are the other half of EU AI Act compliance, and Opsio's free AI readiness assessment writes them for you: answer about forty minutes of questions across fourteen steps, and the moment you send them you get a readiness score and four documents built from your answers.
Who is accountable for AI, how a use case moves from idea to operation, how risk is classified and which tools are approved.
EU AI Act hooks
Which AI tools and accounts staff may use, what may and may not be entered, how outputs are checked and how incidents are reported.
EU AI Act hooks
Twenty-three sections for assessing an AI supplier, from data, privacy and security to contracts, oversight, agents and exit.
EU AI Act hooks
The record that decides whether a use case may proceed: purpose, data, oversight, legal mapping, classification, controls and approval.
EU AI Act hooks
Your acceptable use policy names the AI tools staff may use. Vault AI is a tool you can name there and then prove: models in the EU, personal data pseudonymised before the model, passwords refused, and every call on the audit record. The vendor checklist has its answers ready in the Vault AI document set.
A private endpoint, a portal your security and finance teams will use, and the paperwork your DPO and auditors expect.
Five steps companies take once AI is safe to use on real data.
Give staff a sanctioned, governed AI service they will actually use — instead of personal accounts.
One approved endpoint and portal for the whole company.
Customer service, document analysis, code and contracts — on real customer data, safely.
Production AI on personal data, without exposing it to the model.
Answer security questionnaires and customer audits with evidence instead of assurances.
A downloadable evidence pack and GDPR document set.
Switch or combine Claude, Nova and Mistral without re-engineering or re-assessing your privacy controls.
Simple model aliases; controls stay the same.
Prepare for the EU AI Act, NIS2 and DORA with a single record of how AI handles your data.
An AI Act register and impact-assessment record.
Opsio Vault AI is a managed private AI service. Your applications and teams get leading large language models through one secure API and one portal, and the privacy controls are enforced by the platform itself instead of promised in a policy. Opsio runs it, patches it, monitors it and answers for it under a data processing agreement.
Whichever AI service you use, your organisation stays accountable for the personal data in every prompt, as controller under the GDPR. You need to know where prompts are processed, whether they are stored or used for training, and be able to prove it. Vault AI answers those questions by design: EU inference, personal data pseudonymised before the model, no transcript store at Opsio, secrets refused before any model call, and an audit record for every call.
Model inference stays in the EU. The platform runs in AWS Frankfurt, and every model is called through an EU inference profile or in Frankfurt itself; non-EU model routes are blocked at three separate layers, and CloudTrail logs confirm it. Our email provider, Resend, is a US-based sub-processor: it receives recipient addresses and message metadata for sign-in codes and service notifications, never prompts.
Vault AI detects personal data and replaces it with pseudonymous tokens before the model sees the prompt, then restores the real values on the way back to your app. Each customer has its own token key. Detection is automated, so your privacy profile also sets which data classes may be sent at all.
Opsio keeps no transcript store and no training corpus: prompts and answers are held in memory only while the request runs. Bedrock model-invocation logging is off, and Amazon Bedrock does not use your data to train models or share it with model providers.
Opsio acts as processor under an Article 28 DPA. Model inference, the platform and audit records run in AWS EU regions. Sign-in codes and service notifications are sent through Resend, a US-based sub-processor, under the EU Standard Contractual Clauses and the EU-U.S. Data Privacy Framework; Resend receives recipient addresses and message metadata, never prompt content. You receive the full GDPR document set: DPA, records of processing, DPIA, transfer impact assessment, sub-processor register, retention schedule and a data-subject request runbook.
25 models are offered today — Anthropic: Claude Opus 5.5, Claude Opus 5, Claude Opus 4.8, Claude Opus 4.7, Claude Opus 4.6, Claude Opus 4.5, Claude Sonnet 5, Claude Sonnet 4.6, Claude Sonnet 4.5, Claude Haiku 4.5; Amazon: Amazon Nova 2 Lite, Amazon Nova Pro, Amazon Nova Lite, Amazon Nova Micro, Titan Text Embeddings V2, Titan Embeddings G1 – Text, Titan Multimodal Embeddings G1, Amazon Rerank 1.0; Mistral AI: Pixtral Large, Devstral 2 123B; NVIDIA: Nemotron 3 Super 120B; Cohere: Cohere Embed v4, Cohere Embed English v3, Cohere Embed Multilingual v3, Cohere Rerank 3.5. Each company gets its own approved catalogue with simple aliases such as claude-sonnet, and every model is processed in the EU.
No. Vault AI supports both the Anthropic Messages API and the Amazon Bedrock Converse API. Existing applications, Anthropic SDKs, AWS SDKs and tools that let you set a custom endpoint keep working — you change a base URL and a key. Each application gets its own key, which you can set to expire and revoke at any time.
Yes. Opsio's free AI readiness assessment (opsiocloud.com/ai-governance-and-readiness-assessment-questionnaire/) takes about forty minutes across fourteen steps. When you send it you get a readiness score and four documents written from your answers: an AI Governance Framework, an AI Acceptable Use Policy, an AI Vendor Due Diligence Checklist and an AI Risk Assessment Template. Vault AI then covers the technical side: it can be the approved AI tool your policy names, with EU-only models, pseudonymised personal data and an audit record for every call.
Tell us how your organisation wants to use AI, and we'll show you how Vault AI keeps it compliant.
Ask for the GDPR document set, the evidence pack, the supported-model list or pricing. We'll respond with a structured next step within one business day.
Get a slot with Johan or Fredrik this week.
A short brief is enough — we'll reply with a structured next step.