Skip to content

A note from the founder

April 2026

I built Aegis Firma because every time I looked at existing compliance tools, I saw the same thing: software designed for auditors, not for the people actually responsible for making sure AI is used safely inside organisations.

The regulations are real. The EU AI Act has teeth. GDPR enforcement is accelerating. US state AI laws are multiplying faster than any team can track. But the tools available to deal with all of this were either dense spreadsheets passed around by Big Four consultants, or enterprise platforms that cost €150,000/year and took six months to implement. Neither of these options helps the DPO at a 40-person SaaS company who is also the Head of Legal and somehow responsible for AI governance too.

So I started from the problem: what does a small, well-intentioned organisation actually need to demonstrate responsible AI? Not to tick boxes — but to genuinely reduce risk, protect the people their systems affect, and survive an audit if one comes? That question shaped every feature decision. The compliance assessment is not a questionnaire that dumps a report nobody reads. The document generation does not produce boilerplate that a lawyer would immediately throw away. The training is not a GDPR video from 2018 with 60% completion rates.

There are things I am not willing to do. I will not sell your compliance data. I will not train AI on your DPIAs. I will not obscure how our AI features work or pretend we have certifications we haven't earned. The trust pages on this site are not marketing — they are documentation. If something on there is wrong, email me and I will fix it.

Aegis Firma is a small team. We do not have a dedicated sales department or a VP of Customer Success whose job is to upsell you. What we have is a genuine belief that AI compliance should be accessible to every organisation deploying AI — not just the ones that can afford an army of consultants. That belief is what gets us up in the morning, and it is what this product is built around.

If you are working on AI compliance and you want to talk — about the product, the regulations, what you are trying to achieve — my door is open. Email me directly: founder@aegisfirma.com.

CIQ

The Aegis Firma Team

founder@aegisfirma.com

What we believe

Compliance is not a checkbox exercise

Done well, AI compliance protects people — job applicants, patients, consumers — from the real harms that poorly governed AI causes. Done badly, it creates a paper trail that provides no protection to anyone. We are building for the former.

Small organisations deserve the same tools as enterprises

The GDPR does not offer a SME exemption. The EU AI Act does not either. But enterprise compliance platforms do offer an enterprise price tag. We believe a 10-person company should be able to demonstrate the same rigour as a 10,000-person one, at a price that doesn't require a board approval.

Transparency is a competitive advantage, not a liability

We publish our sub-processor list, our data residency details, our uptime, our incident history. Not because we are legally required to (we are, but that's not the reason). Because organisations that are genuinely trustworthy have nothing to hide.

AI compliance will get harder before it gets easier

Regulations are multiplying. Enforcement is starting. The organisations that build compliance infrastructure now — before the enforcement wave — will spend a fraction of what late-movers will. We are here to be that infrastructure.

Learn more