Legal · Compliance Checklist
Compliance Checklist
A transparent snapshot of OMS AI Nexus™'s legal and compliance posture across policies, privacy law, security, and AI governance.
Policies
- ReadyTerms of Service published
- ReadyPrivacy Policy published
- ReadyData Processing Policy published
- ReadyRefund Policy published
- ReadyUser Agreement published
- ReadyAI Usage Policy published
- ReadySecurity overview published
GDPR / UK GDPR
- ReadyController/processor roles defined
- ReadySub-processor list & 30-day change notice
- ReadySCC 2021 / UK IDTA for international transfers
- ReadyData subject rights response process (≤30 days)
- Ready72-hour breach notification commitment
- ReadyFull DPA available on request for enterprise
CCPA / CPRA
- ReadyNotice at collection & 'Do Not Sell/Share' commitment
- ReadyConsumer request intake via legal contact
Security
- ReadyTLS 1.2+ in transit, AES-256 at rest
- ReadyRLS on every tenant table (100%)
- ReadyMandatory MFA (AAL2) for admins & Founder
- ReadyAudit logs (auth, admin, workspace)
- ReadyBackup & DR drill (RTO ≤ 1h)
- RoadmapISO/IEC 27001 external certificationControls mapped; audit pending
- RoadmapSOC 2 Type II reportEvidence collection in progress
AI Governance
- ReadyAI Usage Policy aligned with ISO/IEC 42001
- ReadyNIST AI RMF (Govern/Map/Measure/Manage) mapping
- ReadyEU AI Act Article 5 prohibited-use enforcement
- ReadyHuman-in-the-loop for high-impact workflows
- ReadyVeracity score + Analytics-Ladder tag on outputs
- RoadmapModel risk register & red-team cadence
Consumer
- Ready14-day satisfaction refund window
- ReadyEU/UK statutory right of withdrawal respected
- ReadyAge gating (16+ or local age of digital consent)
Accessibility
- RoadmapWCAG 2.1 AA target for public pages
"Ready" = enabled in the current platform. "Roadmap" = mapped and in progress. Not a certification.