Data Residency
privacy.residency.availableWhether the provider publicly documents data residency for the relevant product or plan scope.
GDPR Art. 5AgentenTrust 2.0 · EU Evidence Layer
Direct answer: AgentenCode maps field-level product evidence to relevant governance and legal contexts. It shows what is documented, the scope in which it applies, when it was checked and which primary source supports it. It does not label an AI agent as “EU AI Act compliant” or “GDPR compliant” based on isolated features.
EU AI Act
AgentenTrust surfaces evidence related to logging, human oversight, transparency, robustness and cybersecurity. A mapping means that the field can be relevant to an assessment. It does not mean a particular legal obligation automatically applies to every product or deployment.
GDPR
Residency, customer-data training, retention, DPAs, subprocessors, processing scope and security controls are stored as separate evidence fields. No single documented feature can establish GDPR compliance for a concrete use case.
EU Control Map
The cards describe semantic mappings. Concrete agent values come from the shared governance dataset and remain bound to scope, verification date and primary source. A control can be documented, explicitly negative, carry a documented value, or remain unknown.
privacy.residency.availableWhether the provider publicly documents data residency for the relevant product or plan scope.
GDPR Art. 5privacy.residency.customer_region_selectableWhether customers can select a documented processing or hosting region for the relevant scope.
GDPR Art. 5privacy.residency.regionWhich region or regions are explicitly named by the primary source.
GDPR Art. 5privacy.training.customer_dataWhether the primary source explicitly says customer data is or is not used for model training.
GDPR Art. 5security.encryption.at_restDocumented encryption of stored data within the stated product scope.
EU AI Act Art. 15 · GDPR Art. 32security.encryption.in_transitDocumented encryption for data in transit.
EU AI Act Art. 15 · GDPR Art. 32security.customer_managed_keyWhether customer-managed encryption keys or BYOK are documented.
EU AI Act Art. 15 · GDPR Art. 32security.soc2_type2Whether SOC 2 Type II coverage is publicly documented for the relevant product scope.
EU AI Act Art. 15 · GDPR Art. 32governance.sso.samlDocumented support for SAML single sign-on.
EU AI Act Art. 15 · GDPR Art. 32governance.sso.oidcDocumented support for OIDC single sign-on.
EU AI Act Art. 15 · GDPR Art. 32governance.scimDocumented support for SCIM provisioning.
EU AI Act Art. 15 · GDPR Art. 32governance.rbacDocumented role-based access control.
EU AI Act Art. 15 · GDPR Art. 32governance.custom_rolesDocumented custom or granular administrative roles.
EU AI Act Art. 15 · GDPR Art. 32governance.human_approvalDocumented human approval inside an agentic workflow.
EU AI Act Art. 14governance.approval.pre_actionDocumented approval before a consequential or sensitive action is executed.
EU AI Act Art. 14governance.human_oversightDocumented mechanisms for human oversight of agent behavior.
EU AI Act Art. 14governance.permission_controlsDocumented permission controls for agents or workflows.
EU AI Act Art. 14governance.policy_controlsDocumented policy controls that constrain agents or actions.
EU AI Act Art. 14governance.tool_permissionsDocumented controls over which tools an agent may use.
EU AI Act Art. 14governance.action_permissionsDocumented controls over which external actions an agent may execute.
EU AI Act Art. 14governance.delegation_controlsDocumented limits on delegation to other agents or components.
EU AI Act Art. 14governance.kill_switchDocumented ability to stop or disable agentic execution.
EU AI Act Art. 14governance.rollbackDocumented rollback or recovery after agent actions.
EU AI Act Art. 14governance.audit_logs.availableWhether audit or compliance logs are publicly documented.
EU AI Act Art. 12governance.audit_logs.retention_daysDocumented retention period for audit or compliance logs.
EU AI Act Art. 12governance.audit_logs.apiWhether audit logs can be retrieved programmatically through an API.
EU AI Act Art. 12governance.audit_logs.siem_exportWhether export or integration with SIEM systems is documented.
EU AI Act Art. 12observability.availableWhether observability or monitoring capabilities are documented.
EU AI Act Art. 12observability.tracingWhether execution traces are documented for agentic runs.
EU AI Act Art. 12governance.audit_logs.action_levelWhether individual agent actions can be traced at audit level.
EU AI Act Art. 12privacy.retention.policyDocumented retention or deletion logic for relevant customer or product data.
GDPR Art. 5privacy.dpa.availableWhether a Data Processing Agreement is publicly documented for the relevant scope.
GDPR Art. 28privacy.subprocessors.list_availableWhether the provider publishes a current list of subprocessors for the relevant scope.
GDPR Art. 28privacy.processing.scopeThe product, plan, region or deployment scope to which a privacy or processing statement actually applies.
GDPR Art. 5 · GDPR Art. 28security.secrets.credential_handlingDocumented handling of secrets, tokens or credentials in the relevant agent or platform scope.
EU AI Act Art. 15 · GDPR Art. 32governance.activity_history.availableWhether an activity or execution history is documented for relevant agent actions.
EU AI Act Art. 12Interpretation rules
If AgentenCode cannot find sufficiently specific public evidence, the field remains unknown. Missing documentation is not converted into a negative claim.
A negative value is stored only when a reliable primary source explicitly documents non-availability, a prohibition or another negative state.
Enterprise-only evidence remains enterprise-only. Plan, region, hosting mode, channel and administrative configuration can materially change what a documented control means.
Official product, security, privacy, legal and technical documentation has priority. Third-party summaries do not silently become product facts.
Start with the controls that matter for your deployment: identity, permissions, data handling, auditability and human control. Use AgentenCode to see which points are publicly documented and which are still evidence gaps. Then verify the exact plan, region, tenant configuration and contractual terms with the provider before making a procurement, security or legal decision.
For example, “SAML SSO is documented” is useful evidence about enterprise access control. It is not proof that every plan has SAML, that the implementation meets your internal policy, or that the product is legally suitable for a particular processing activity. The same rule applies to data residency, human approval, audit logs and every other control.
The visible EU layer is backed by structured public datasets. governance.json contains agent-level governance signals; eu-controls-en.json exposes the English control map; trust-controls.json defines the normalized control taxonomy. This keeps the human-readable page, the comparison tools and machine-readable evidence aligned.
Field-level trust history is stored separately from the current state. When a verified field changes after the baseline, the history model can preserve its previous value, new value, scope, verification date and source rather than silently overwriting the past.
No. AgentenCode shows documented product and governance evidence and maps controls to relevant legal contexts. Whether a legal obligation applies depends on the specific system and use case.
No. Data residency is one evidence field. It does not by itself establish lawful processing, transfer compliance, processor obligations, retention rules or security adequacy.
Because public evidence may be missing, too broad, plan-specific or ambiguous. AgentenCode keeps that uncertainty visible instead of guessing.
Yes, but corrections are evaluated against the same source-first methodology. A provider relationship or submission does not buy a positive status or ranking.