Article 50 transparency duties are now applicable. See what applies →

Trust & Security

Security built around company separation

EU AI Passport protects company AI inventory, readiness documents, learner information and evidence records through authenticated access, organization scoping and managed cloud infrastructure.

Access and tenant separation

  • Authenticated company workspaces and protected customer routes.
  • Organization-scoped application and database access controls.
  • Restricted backend-only records for credentials, sessions, commercial orders and manual activations.
  • Audit records for important operational actions.

Hosting and infrastructure

Application hosting and serverless functions are provided by Netlify. Authentication, database and storage services are provided by Supabase. The production Supabase project is hosted in EU West (Ireland). Netlify serves static content through its CDN and currently runs the production functions in its US East infrastructure.

View sub-processors

Encryption and handling

  • Connections to EU AI Passport use HTTPS/TLS in transit.
  • Managed infrastructure providers apply their standard protections for stored data.
  • Customer workspace data is not sold and is not used to train AI models.
  • Customers should avoid entering sensitive information that is not required for their readiness work.

Retention, export and deletion

Retention depends on the service and operational record involved. Customers may request access, correction, export or deletion where applicable by contacting us. Certain records may need to be retained where required for security, audit, payment, legal or evidence purposes.

Security assurance

EU AI Passport does not currently claim ISO 27001, SOC 2 or another formal security certification. The platform continues to improve its security, privacy and operational controls as the service develops.

Contact

For a security or privacy question, contact info@euaipassport.com.

Privacy Policy · Legal Notice