AI docs agent AUM markets itself to law firms and hospitals as "HIPAA, GDPR, SOC2 aligned"; no certification is published
AUM sells itself into legal, healthcare, financial and government work on the strength of a compliance claim it does not back with an auditor, a certificate or a report.
AUM, an AI agent that drafts documents, proposals and emails, markets itself directly to law firms, hospitals, financial institutions and government agencies on the strength of a single line: "Compliance-Ready HIPAA, GDPR, SOC2 aligned architecture," according to its website.
The company names specific regulated buyers by name. For law firms, it offers "contract analysis, legal research, due diligence & compliance reporting — 100% client data protection." For healthcare, "HIPAA-compliant patient data analysis, clinical knowledge retrieval, research copilots." For financial institutions, "investment research, compliance documentation, secure deal document parsing." For government and defense, "classified intelligence search, secure policy research, zero-cloud deployment."
AUM backs the pitch with deployment options rather than paperwork. The product can run "on-premise," in a "private cloud / VPC," or on "air-gapped infrastructure" that is "completely isolated," and the company says customers can "deploy and operate fully offline — from air-gapped servers to remote locations." It states plainly that "your data never leaves your premises." Access is gated by "secure role-based access control" with "granular permissions and user management."
What the site does not publish, for any of the three named frameworks, is a certificate, an auditor, a SOC 2 report type or date, or a GDPR compliance mechanism. "Aligned architecture" is a design claim, not an attestation, and AUM does not claim to hold certification under any of the three regimes it names. The company also discloses no logging or audit-trail mechanism, no insurance or liability cover, and no settlement terms tied to whether its output is used correctly — the product is offered on a "forever free" tier with no outcome-linked pricing.
AUM is not alone in this pattern. AI Dispatch has repeatedly found vendors that name compliance frameworks as a marketing shorthand for architecture choices — on-premise hosting, access controls, data residency — without the underlying certification those names imply to a regulated buyer.
Entries in this piece 1
Published index entries backed by the same source documents this piece cites.
Sources 9
“Compliance-Ready HIPAA, GDPR, SOC2 aligned architecture”
aumbot.co · checked Aug 2, 2026“On-Premise Servers Deploy directly on your hardware infrastructure Private Cloud / VPC Secure cloud deployment within your virtual private cloud Air-Gapped Infrastructure Completely isolated systems for maximum security Multi-Device Local Distributed deployment across multiple local devices”
aumbot.co · checked Aug 2, 2026“Your data never leaves your premises”
aumbot.co · checked Aug 2, 2026“Secure Role-Based Access Control Granular permissions and user management”
aumbot.co · checked Aug 2, 2026“For Law Firms Contract analysis, legal research, due diligence & compliance reporting —”
aumbot.co · checked Aug 2, 2026“100% client data protection. For Healthcare HIPAA-compliant patient data analysis, clinical knowledge retrieval,”
aumbot.co · checked Aug 2, 2026“research copilots. For Financial Institutions Investment research, compliance documentation, secure deal document”
aumbot.co · checked Aug 2, 2026“parsing. For Government & Defense Classified intelligence search, secure policy research, zero-cloud”
aumbot.co · checked Aug 2, 2026“Deploy and operate fully offline - from air-gapped servers to”
aumbot.co · checked Aug 2, 2026