EU AI Passport uses a small number of third-party providers to deliver the product — for hosting, authentication, database, storage and email. This page lists each provider we currently use, what we use them for, the types of data involved, and their role. We will keep this list updated as our provider set evolves.
| Provider | Purpose | Data types | Region | Role | Notes |
|---|---|---|---|---|---|
| Netlify ↗ | Application hosting and serverless functions | Application traffic, request logs | Static hosting: Global CDN · Serverless functions: IAD — N. Virginia, United States | Processor | Hosts the EU AI Passport website and backend API functions. |
| Supabase ↗ | Authentication, database and storage | Account credentials, company profile, AI inventory, documents, learner records, certificates | West EU (Ireland), eu-west-1 | Processor | Stores authenticated workspace data and evidence records. |
| OpenAI ↗ | AI-assisted Compliance Copilot and governed generation features | Feature prompts and the limited workspace context supplied to the AI-assisted operation | Provider infrastructure; processing location depends on the applicable OpenAI service configuration | Processor / service provider | Called from authenticated server-side AI features. Customer workspace data is not used by EU AI Passport to train models. |
| Resend ↗ | Transactional email | Recipient email address, message content of transactional emails | Ireland, eu-west-1 | Processor | Sends invite, notification and account emails. |
| ImprovMX ↗ | Email forwarding | Email addresses and message content sent to company mailboxes | France, OVH data centres for EU customer data | Processor | Forwards mail sent to @euaipassport.com addresses. |
| Stripe ↗ | EU subscription checkout and payment processing | Billing details, payment transaction metadata and payment-method data entered on Stripe-hosted checkout | Stripe infrastructure; processing location depends on the applicable Stripe service configuration | Payment processor / service provider | EU AI Passport redirects authenticated subscription purchases to Stripe-hosted secure checkout. Card data is entered on Stripe and is not collected directly by the EU AI Passport application. |
iyzico ↗ — Türkiye payment integration is implemented but live production payment processing is not enabled. It will move to the active table when production approval and live processing are enabled.
This list reflects the providers integrated into EU AI Passport as of today and may change as the product evolves. It is provided for transparency and is not a data processing agreement. For privacy or security questions, or to request more detail about a specific provider, contact us at info@euaipassport.com. See also our Trust & Security page.