Counsel reviewing an AI platform needs three things: to know who processes the data, to see the paper, and to confirm the obligations regulators care about are met by the product — not by a promise. Five questions, answered plainly, with the documents a request away at hello@turtleaicoworker.com.
The theme across the answers: oversight and record-keeping aren't compliance features bolted on for the review — they're how execution works. That makes the diligence shorter, because the evidence already exists.
The subprocessor list is published on the Trust Center, and it's short: infrastructure hosting, and the model providers — who only ever see a prompt when an agent is configured to use them. With BYO keys, model requests run under your own agreement with the provider, not through terms we negotiated for you. No silent additions: the list changes only when the product does.
The subprocessor listYes — a Data Processing Agreement is available on request, including standard contractual clauses where applicable. We'd rather send you the actual document than paraphrase it on a marketing page, so ask and it arrives.
Request the DPAThe two things AI regulation keeps asking for — effective human oversight and complete records of automated decisions — are how the platform already works. Human-in-the-loop approval gates with single-use grants sit in the execution path, and every run and tool call is logged with who authorized it. The Trust Center maps these controls to the EU AI Act and NIST AI RMF in those frameworks' own vocabulary.
The framework mappingPer-workspace retention policies govern audit and compliance data, and a legal hold freezes any purging while exports stay available — for litigation, investigation, or a regulator's clock. Evidence is exportable in the shape a reviewer asks for it: filterable by workspace, worker, integration, user and date.
Audit and retentionIt never trains on your data — workspace content (tables, knowledge, chats, traces) is never used to train models, ours or anyone else's. Unapproved writes are a no-op: the runtime authorization floor stops them before execution, whatever the prompt said. And a per-workspace PII policy detects emails, phones, SSNs, card numbers, addresses and names, with mask, hash, remove and flag redaction modes.
The enforcement layerThe documents and mappings your review will actually cite.
SOC 2, ISO 42001, NIST AI RMF and EU AI Act concerns mapped to the platform controls that produce evidence for them. A control mapping, not a certification claim.
Read the mappingThe Data Processing Agreement itself, with SCCs where applicable — the document, not a summary of it.
Request by emailA short assessment of your organization's current AI controls — a useful baseline before you review ours.
Run the checkThe oversight mechanics behind these answers: Approvals for the human-in-the-loop gates, Governance for policy enforcement. Your security counterparts have their own page at /for/it-security.
The DPA, the subprocessor list, and answers to counsel's questions — from someone who can speak to how the product actually enforces what the paper says.