Skip to content
Free Tool — No Login Required

Compare AI vendors on compliance

Pick up to 4 tools and see their data-handling and certification positions side by side.

Choose vendors (2 of 4)

DimensionChatGPT (OpenAI)Claude (Anthropic)

Overall risk posture

Aegis Firma’s summary read of the vendor’s published position for regulated business use.

Medium riskLow risk

DPA available

A Data Processing Addendum is a precondition for lawful processing of personal data under GDPR. Without one, the deployment is hard to defend at all.

YesYes

Trains on your data

Whether your inputs feed model training. "No" is the posture you want — training on customer data creates a disclosure and purpose-limitation problem under GDPR.

NoNo

Data retention

How long inputs are held. Shorter is better for data-minimisation; zero-retention modes are the strongest position.

30 days30 days

SOC 2 (vendor-published)

The vendor states it holds SOC 2. Aegis Firma has NOT read any SOC 2 report — they are issued under NDA and cannot be verified by an outsider. Request it from the vendor.

Vendor states yesVendor states yes

GDPR posture

Whether the vendor publishes a GDPR-aligned processing position (DPA, SCCs, transfer mechanism).

DocumentedDocumented

EU data residency

Whether data can be kept in the EU. Absence is not fatal — SCCs can cover transfers — but residency materially simplifies the transfer analysis.

Not by defaultNot by default

EU AI Act tier

The vendor’s own model tier. Your obligations depend on YOUR use of the tool, not only on the model’s tier — a minimal-risk model used for hiring still puts you in Annex III.

GPAI — Standard (not systemic risk)GPAI — Standard (not systemic risk)

Fit by use case

Your obligations follow how YOU use the tool, not the vendor’s model tier.

Use caseChatGPT (OpenAI)Claude (Anthropic)
Customer support (no PII)
Content generation
Internal productivity
Medical / legal advice
HR decisions (hiring, firing)
Processing sensitive personal data
Suitable Caution Avoid Not rated for this vendor

ChatGPT (OpenAI)

Positions as of April 2026

Acceptable for most business use cases with a signed DPA. Not suitable for sensitive personal data of EU residents without additional safeguards. Enable zero data retention API mode for maximum privacy.

Full risk breakdown →

Claude (Anthropic)

Positions as of April 2026

One of the better privacy postures among major AI vendors. DPA available. Best for organizations prioritizing privacy and safety alignment. Enable zero retention API flag for sensitive use cases.

Full risk breakdown →

Where this comes from · positions as of April 2026

Vendor-published trust documentation (each vendor's own trust centre, security page, DPA and EU AI Act statements), compiled by Aegis Firma. Aegis Firma has not audited these vendors and has not reviewed their SOC 2 reports — those are issued under NDA and must be requested from the vendor directly.

This is informational, not legal advice. This table restates positions the vendors themselves publish. Aegis Firma has not audited these companies and has not read their SOC 2 reports — those are issued under NDA and must be requested from the vendor directly. Verify against the vendor’s own trust documentation before making a procurement decision, and consult qualified legal counsel on your specific deployment.

Picking the vendor is the easy half

Aegis Firma tracks which of your AI tools touch regulated decisions, and generates the assessments and disclosures each one needs.

Start free