
Company & trust
Governance, security and operational readiness.
G66 is a technology and operations group. We build and run the software that lets companies operate with agents doing the repeatable work and a smaller team holding the accountable work. This page summarises how we are structured and how we deliver.
What G66 is, in one paragraph.
G66 is a technology and operations firm. The entities below are the group's contracting vehicles: you sign with the one in your region and the same team delivers. The word Capital in two legal names is history, not a business line. G66 does not manage third-party money and is not a financial institution. Structuring is a separate, smaller practice, contracted on its own and executed with licensed advisers.

How we deliver
Delivery
Segregated environments, least-privilege access, disciplined SDLC with review, testing and release control. Delivered into infrastructure the client controls, with documentation and handover.
Data
Confidential by default. Access limited to delivery personnel. Handling aligned to client policy and applicable law.
AI governance
Prompt and model versioning, an evaluation set per workflow, a human in the loop where the decision has legal or financial effect, full audit trail. We state which controls are implemented in each engagement; we do not claim controls we have not put in.
Documentation
Corporate documents, licences and address verification available to banks and regulated partners on request, under NDA.
Regulatory context we build for
EU AI Act
Each workflow is classified by use case before it is built. Where a decision falls in the Act's high-risk categories, a named person decides and the agent prepares. Logs, evaluation sets and model versions form the technical documentation.
DORA
For financial entities we deliver as an ICT third-party provider: data for the register of information, contractual clauses on access, audit and exit, incident-reporting support and testing evidence.
GDPR and data residency
Processor terms, data minimisation, records of processing, no training on client data. EU regions for model providers and infrastructure where the client requires it; own infrastructure or on-premise where that option does not exist.
Certifications
G66 does not hold ISO 27001 or ENS certification today and does not claim it. Controls are aligned to ISO 27001 Annex A and documented per engagement; the certification roadmap is available on request.
Compliance with these frameworks remains the obligation of the regulated entity. We build so that its evidence exists.
Request the documentation.
Corporate, security and delivery documentation, under NDA, within two working days.
