The EU-US Data Privacy Framework, explained for vendor reviews
Solomon Amos · 7 Sep 2026 · 10 min read
For each regulation, how many of the requirements it places on your vendors Within’s public evidence reaches. Open one for every item with its date and source.
What the vendor lists, typed; public items can be read now, the rest are available on request.
3 documents listed on Within’s trust centre
trust.within.aiAnswers the vendor publishes to questions buyers ask, quoted with the link to where it says so.
Where data is hosted or processed
Where is the data stored?
“All data is stored within secure data centers in the United States, using Amazon Web Services (AWS).”
Regions named: USas of 21 Sep 2026Source
Encryption
How is the data protected and encrypted?
“Data is encrypted using industry-standard methods (AES-256 at rest and TLS 1.2 or higher in transit). Access to servers and databases is tightly restricted and monitored through role-based access and multi-factor authentication.”
as of 21 Sep 2026Source
Use of customer data to train models
What policies are in place to prevent data retention and model training with sensitive customer data?
“Within’s Data Retention Policy outlines how long data is kept and how it is securely disposed of after that period. Within’s AIMS Policy describes how AI systems are used and ensures customer data is never used to train AI models.”
as of 21 Sep 2026Source
Use of customer data to train models
Does Within train AI models using customer data?
“No. Within does not use customer data to train AI models.”
as of 21 Sep 2026Source
Penetration testing
Are there regular security audits and penetration tests conducted?
“Yes. Within conducts security audits and penetration tests at least annually, using both internal processes and third-party assessments to ensure ongoing security.”
as of 21 Sep 2026Source
Solomon Amos · 7 Sep 2026 · 10 min read
CertReports Research · 18 Sep 2026 · 12 min read
This maps third-party obligations to the vendor evidence that may support them. It is not legal advice and never a statement that a vendor or its customers comply; confirm scope and sufficiency with your counsel or auditor. “No public evidence” means nothing public was found at the last check. Citations link to the official text.