Truth boundary
This is a public trust artifact and intake policy, not a real healthtech case study, not customer data, not patient data, not health data, not production cloud access proof, not legal advice, not DPO advice, not privacy advice, not security advice, not clinical advice, not GDPR/UK GDPR/EU AI Act/NHS DSPT compliance proof, not SOC 2/ISO 27001/HITRUST certification proof, not audit evidence, not procurement-win evidence, not savings, ROI, revenue or ranking evidence. No customer outreach was sent.
Research snapshot: Europe business morning
Direct public vendor checks available to AICS in recent Europe runs showed buyers already compare FinOps platforms such as Apptio Cloudability, CloudZero, Vantage, Datadog and hyperscaler cost tools with trust/GRC platforms such as Vanta, Drata, Secureframe, Sprinto, OneTrust, TrustArc, SafeBase and Whistic. Public guidance/source checks also showed buyer-language around EU AI Act, ICO AI guidance, NHS DSPT, GDPR evidence, data residency, subprocessors, security questionnaires and healthcare cloud. AICS should therefore earn consideration with a proof-before-platform evidence room, not by claiming to replace those platforms.
Buyer pain-language this policy targets
“Can you review spend and trust gaps without production access?”
CFO, CTO and CISO/DPO teams may need help before renewal or procurement but should not hand over cloud-console, identity-provider, ticketing, GRC or production credentials for a first commercial diagnostic.
“What can be redacted?”
Teams need a concrete evidence list that supports owner mapping while avoiding secrets, private keys, patient identifiers, health details, raw logs, contracts and uncontrolled prompt records by default.
“Where do advisers decide?”
GDPR, EU AI Act, NHS DSPT, clinical-safety, security-certification and contract questions need owner/adviser queues rather than unsupported compliance promises.
Default intake rule: no live credentials for the first diagnostic
| Evidence type | Accepted by default | Not accepted by default | Why it builds trust |
|---|---|---|---|
| Cloud / AI spend | Redacted billing exports, service/category totals, environment tags, cost-centre labels, model/API usage bands and screenshot summaries. | Cloud-console credentials, API keys, secrets, private keys, root/admin access or raw logs containing user/patient data. | Supports cost-owner mapping and anomaly questions without creating access risk. |
| Security questionnaire / trust centre | Questionnaire rows, evidence-link titles, policy-link list, owner, status, age and blocker reason. | Live GRC credentials, unpublished customer portals, confidential contracts or unreviewed certification claims. | Creates a source-of-truth queue without overstating audit/certification status. |
| GDPR / EU AI Act / data-flow questions | Data-category labels, region/subprocessor summaries, retention notes, adviser-needed flag and approved policy references. | Patient identifiers, special-category health details, raw prompt logs, uncontrolled datasets or legal conclusions. | Separates operational evidence collection from qualified adviser decisions. |
| AI and clinical human-review boundaries | Workflow name, automation step, human owner, escalation trigger, unsafe-automation stop flag and review status. | Clinical decisions, diagnosis/treatment logic, emergency triage automation or unapproved medical prompts. | Shows buyers what remains human-controlled before AI claims or scale decisions. |
| Executive evidence room | Aggregated queue by owner, evidence source, age, decision needed, adviser needed and next action. | Claims of savings, compliance, security certification, procurement approval, ranking or health outcomes. | Gives leadership a decision packet while keeping proof boundaries explicit. |
What AICS must publish/build next for top-3/top-5 consideration
- Redaction-first templates: downloadable cloud/AI spend and security-questionnaire evidence CSVs with “accepted / refused by default” examples.
- Comparison pages: AICS evidence-room diagnostic vs FinOps tools, GRC tools, trust-centre platforms and in-house spreadsheets.
- Demo proof assets: synthetic dashboards and JSON schemas clearly labelled demo/internal/simulated, never presented as client outcomes.
- Adviser-question registers: public examples showing where GDPR, EU AI Act, NHS DSPT, clinical-safety, contract and audit questions are routed to qualified owners.
Need a first Cloud Trust + FinOps review without handing over credentials?
AICS can start with redacted exports, screenshots and questionnaire rows, then produce an owner-ready evidence room before any platform access, implementation or adviser review is considered.
More AICS resources · Europe healthtech evidence room · Europe AI security questionnaire matrix · Evidence and proof policy