Touchstone is the governance layer for teams shipping AI into legal, privacy and security minefields. A repeatable methodology — survey, guide, build, audit, ship — wrapped around the eight domains regulators actually care about.
Tell us where you are. We'll point you to the right corner of the framework.
Five phases. Eight principles. One auditable trail from first prompt to first customer — and every quarterly re-audit after that.
Define the idea, validate the opportunity, pick format and model.
Follow the 8-principle methodology. Session by session, version by version.
Iterate with live AI feedback, version control, and checklist scoring.
8-domain review — design, legal, security, GDPR, QA, flow, FAQs, terms.
Ship with confidence. Monitor in production. Schedule re-audits.
Every Touchstone audit runs the same eight domains, in the same order — so nothing ships blind to a category of risk. Findings are triaged by severity, tied to evidence, and exportable to your evidence vault.
Audit results drive ship / no-ship calls. Request access and we'll open the audit for you within two working days.
Founders are shipping AI into legal, privacy and security minefields they don't know exist. The consequences are documented, accelerating, and now codified into law.
GDPR fines issued in 2023 — a record high, up 168% YoY.
Maximum EU AI Act fine — or 7% of global turnover.
GDPR breach notification window. Most AI startups have no process.
Of vibe-coded apps ship with no security review.