Security and data
Your AI governance record, protected by design.
This page states where the product runs, what it stores, who can read it, and what we have not built yet. Nothing here is aspirational. If a control is not in place, it is listed as not in place.
The short version
Where the data sits
Three tiers, two of them in Frankfurt.
Tier 1
The customer's browser
Your people, signed in with a magic link.
Tier 2
The application
Vercel — function region fra1, Frankfurt, EU.
Tier 3
Database and file storage
Supabase — eu-central-1, Frankfurt, EU. Encrypted at rest.
Side branch · Assure only
Anthropic API
Carries an anonymised summary. United States — not pinned to an EU region.
Google Analytics runs on the public marketing pages only — a transfer outside the EU that touches visitors to this site, not customer register data. Both non-EU services are set out in full below.
The detail
Open whichever answer you were sent here for.
Where does the product run?
The application and the data behind it are hosted in the European Union, in Frankfurt. That is a deliberate architectural choice rather than a platform default: the hosting region and the database region were both pinned to Frankfurt, and keeping the register in the EU is the standing intent.
Application hosting
Vercel — function region fra1, Frankfurt, EU
Database, authentication and file storage
Supabase — region eu-central-1, Frankfurt, EU
Transactional email
Brevo
Your register never leaves the EU. Two supporting services sit outside it, and both are controlled. Product analytics on the marketing site run on Google Analytics, which touches visitors to the public pages, not customer register data. And on the Assure tier, an anonymised summary of your posture is sent to Anthropic’s API to draft market-sensing commentary. Both are set out in the subprocessor table below.
What information does AI Register actually hold?
AI Register stores governance metadata about the AI systems you use: purpose, vendor, owner, classification, obligations, controls and evidence notes. That is the register.
It does not require, request or receive the prompts you send to those tools, the model inputs or outputs, your production documents, or the data the registered AI tools process. The product never connects to the systems it describes. The narrower the footprint, the smaller the consequence of anything going wrong.
How is the data encrypted, in transit and at rest?
Traffic to and from the application is protected with TLS. Data stored in the database and in file storage is encrypted at rest by Supabase.
We do not publish key-management detail. It is not documented to a standard we would put in front of an auditor, so we leave it out rather than describe it loosely.
Who can read your records — including us?
Sign-in. Access is passwordless: a magic link sent to your email address, with optional Google sign-in. There is no enforced multi-factor authentication and no SSO today.
Tenant isolation. Separation between customers is enforced in the database, not in application code. Postgres row-level security applies to every tenant table, and every such table is scoped by an org_id claim carried in the signed token issued at sign-in.
Acuity administrator access. We will not tell you that only your organisation can see your data. An acuity_admin claim permits Acuity personnel to read customer records, for support and for delivering the Assure service. That access exists, it is deliberate, and it is subject to the same audit log as everything else.
Can the record be altered without leaving a trace?
A register is only evidence if it can be shown to be untampered. Database triggers write an append-only audit log capturing the actor, the actor’s email address, the timestamp, the table, the row and the before and after state of the change.
UPDATE and DELETE on that log are revoked at the database privilege level from every API role, including the service role. The application cannot rewrite its own history, and neither can we.
The same principle runs through the record itself. A classification is superseded rather than overwritten: the earlier classification stays, and the only column a user may change on it is the pointer to the entry that supersedes it. Attestations are insert-only.
Who else touches your data? The full subprocessor list.
The complete list, including the two transfers outside the EU.
| Company | Purpose | Data involved | Location |
|---|---|---|---|
| Vercel | Application hosting | Application requests and responses | Function region fra1 — Frankfurt, EU |
| Supabase | Database, authentication and file storage | Register records, user accounts, uploaded evidence files | eu-central-1 — Frankfurt, EU |
| Brevo | Transactional email | Email address, name, message content | EU |
| Google Analytics | Product analytics on the marketing site | Marketing-site usage data | United States — a transfer outside the EU |
| Anthropic | Drafting market-sensing commentary — Assure tier only | Anonymised posture summary: vendors, classification outcomes, autonomy levels, definition status, counts and matched signals. No organisation name, personal names or customer content | United States. No training on API data; outbound payload anonymised. |
The Anthropic call carries an anonymised summary and applies to the Assure tier only. It contains no organisation name, no company number, no personal names, no user email addresses and none of the content your registered AI systems process. What it does carry is the shape of the estate: vendors, classification outcomes, autonomy levels, definition status and counts. Anthropic does not train models on data submitted through its API. Assure customers who would rather the feature were switched off entirely can ask us to disable it on their account.
What is not in place yet? The security roadmap.
The baseline above is in place today on every plan. The work below is committed and in progress. We publish it because a buyer evaluating a governance product should be able to see the plan, and because this page is where each item will be marked done. We will not date an item until we can stand behind the date.
An independent penetration test
ISO/IEC 27001 or SOC 2 certification
Enforced multi-factor authentication
SSO for Assure customers
Formal periodic access reviews
Published backup and recovery commitments
Is ISO/IEC 42001 an information-security certification? No.
ISO/IEC 42001 is a management-system standard for artificial intelligence. It is not ISO/IEC 27001, and it says nothing about information security. The two are routinely conflated.
Using AI Register does not confer any certification on your organisation, under 42001 or any other standard. The product keeps the record; the certification, if you want one, is a separate exercise with an accredited body.
We say this from inside the standard rather than outside it. Acuity’s assurance work is led by a certified ISO/IEC 42001 Lead Auditor. That is a credential held by a person, not a certification held by this product or by your organisation, and we are careful about the difference.
Ask us the awkward one.
Security questionnaires, subprocessor queries and vulnerability reports go to one address.
The mailbox is monitored during business hours, Irish time.