>· EU AI PASSPORT
Home Guide Compliance Pack AI Literacy Partners Pricing
Profile ▾
Sign in
ENITTR
Free Assessment
Home Guide Compliance Pack AI Literacy Partners Pricing Free Assessment → Italiano
>· EU AI PASSPORT
✕ Close
Legal

Trust & Security

EU AI Passport is designed as a secure readiness workspace for SMEs. We protect company AI inventory, readiness documents, learner information and certificate evidence with account-based access and company-level data separation.

1. Data we protect

  • Company profile
  • AI inventory
  • Assessment results
  • Compliance Pack documents
  • Learner records
  • Training progress
  • Certificates
  • Order/bundle requests

2. Workspace access and company separation

  • Secure sign-in
  • Company-level workspace separation
  • Role-based access foundation
  • Restricted database access
  • Audit trail for key actions
  • Encrypted connection via HTTPS
  • On-device storage (before sign-in) clearly labelled

3. Hosting and infrastructure

EU AI Passport runs on established third-party infrastructure rather than self-hosted servers, so we can focus on the readiness product while relying on our providers’ operational security.

  • Application hosting and serverless functions: Netlify
  • Authentication, database and storage: Supabase
  • Static hosting region: Netlify global CDN
  • Serverless functions region: Netlify IAD — N. Virginia, United States
  • Database region: Supabase West EU (Ireland), eu-west-1

See the full list of sub-processors below.

4. Encryption and transport security

  • All connections to EU AI Passport use HTTPS/TLS encryption in transit.
  • Our infrastructure providers apply encryption at rest as part of their standard hosting configuration.

5. GDPR-ready data handling

  • Data minimisation
  • Purpose limitation
  • Access control
  • Deletion/export request process
  • No sale of customer data
  • No training of AI models on customer workspace data
  • Processor/subprocessor transparency roadmap

6. Data retention and deletion requests

Retention settings are being operationalised for launch customers. Customers may request export or deletion.

To request an export or deletion of your data, contact us at info@euaipassport.com.

7. Sub-processors

We use a small number of third-party providers to run EU AI Passport (hosting, authentication/database, transactional email). See the full list, including purpose, data types and region, on our Sub-processors page.

8. No AI model training on customer workspace data

Customer workspace data is not used to train AI models.

9. Where your data lives

EU AI Passport continuously improves its security, privacy and compliance controls. Signed-in workspaces are stored in Supabase. Before you sign in, entries are saved only on your device.

10. Certification roadmap

We are preparing the operational controls needed for future security certifications and enterprise assurance reviews. Formal certifications such as ISO 27001 or SOC 2 are roadmap items and are not currently claimed.

11. Customer responsibility

  • Do not upload unnecessary sensitive personal data
  • Review generated documents before use
  • Use expert review for sensitive/high-risk use cases

12. Contact

For privacy or security questions, contact us at info@euaipassport.com.

[to be confirmed] · [to be confirmed], [to be confirmed], Italy · VAT/P.IVA: [to be confirmed]

Contact us about security
>· EU AI PASSPORT
Built by Impulso Advisors — Italy
Blog Partners Privacy Terms Refund Trust & Security Sub-processors Contact
EU AI Passport is not an official EU certification, legal opinion, or conformity assessment. It supports AI Act readiness, AI literacy, documentation and internal governance.