Security and data

Your AI governance record, protected by design.

This page states where the product runs, what it stores, who can read it, and what we have not built yet. Nothing here is aspirational. If a control is not in place, it is listed as not in place.

The short version

Hosted in the EUApplication and database both pinned to Frankfurt.
Encryption in transit and at restTLS to and from the application; encrypted at rest by Supabase.
Tenant-isolated accessSeparation enforced in the database, not in application code.
Governance information, not the data your AI tools processNo prompts, no documents, no model inputs or outputs.
Attributable changes and a full historyWho changed what, and when, in a log nobody can rewrite.
Published subprocessorsThe complete list, including the two transfers outside the EU.

Where the data sits

Three tiers, two of them in Frankfurt.

Tier 1

The customer's browser

Your people, signed in with a magic link.

TLS

Tier 2

The application

Vercel — function region fra1, Frankfurt, EU.

TLS

Tier 3

Database and file storage

Supabase — eu-central-1, Frankfurt, EU. Encrypted at rest.

Side branch · Assure only

Anthropic API

Carries an anonymised summary. United States — not pinned to an EU region.

Google Analytics runs on the public marketing pages only — a transfer outside the EU that touches visitors to this site, not customer register data. Both non-EU services are set out in full below.

The detail

Open whichever answer you were sent here for.

Where does the product run?

The application and the data behind it are hosted in the European Union, in Frankfurt. That is a deliberate architectural choice rather than a platform default: the hosting region and the database region were both pinned to Frankfurt, and keeping the register in the EU is the standing intent.

Application hosting

Vercel — function region fra1, Frankfurt, EU

Database, authentication and file storage

Supabase — region eu-central-1, Frankfurt, EU

Transactional email

Brevo

Your register never leaves the EU. Two supporting services sit outside it, and both are controlled. Product analytics on the marketing site run on Google Analytics, which touches visitors to the public pages, not customer register data. And on the Assure tier, an anonymised summary of your posture is sent to Anthropic’s API to draft market-sensing commentary. Both are set out in the subprocessor table below.

What information does AI Register actually hold?

AI Register stores governance metadata about the AI systems you use: purpose, vendor, owner, classification, obligations, controls and evidence notes. That is the register.

It does not require, request or receive the prompts you send to those tools, the model inputs or outputs, your production documents, or the data the registered AI tools process. The product never connects to the systems it describes. The narrower the footprint, the smaller the consequence of anything going wrong.

How is the data encrypted, in transit and at rest?

Traffic to and from the application is protected with TLS. Data stored in the database and in file storage is encrypted at rest by Supabase.

We do not publish key-management detail. It is not documented to a standard we would put in front of an auditor, so we leave it out rather than describe it loosely.

Who can read your records — including us?

Sign-in. Access is passwordless: a magic link sent to your email address, with optional Google sign-in. There is no enforced multi-factor authentication and no SSO today.

Tenant isolation. Separation between customers is enforced in the database, not in application code. Postgres row-level security applies to every tenant table, and every such table is scoped by an org_id claim carried in the signed token issued at sign-in.

Acuity administrator access. We will not tell you that only your organisation can see your data. An acuity_admin claim permits Acuity personnel to read customer records, for support and for delivering the Assure service. That access exists, it is deliberate, and it is subject to the same audit log as everything else.

Can the record be altered without leaving a trace?

A register is only evidence if it can be shown to be untampered. Database triggers write an append-only audit log capturing the actor, the actor’s email address, the timestamp, the table, the row and the before and after state of the change.

UPDATE and DELETE on that log are revoked at the database privilege level from every API role, including the service role. The application cannot rewrite its own history, and neither can we.

The same principle runs through the record itself. A classification is superseded rather than overwritten: the earlier classification stays, and the only column a user may change on it is the pointer to the entry that supersedes it. Attestations are insert-only.

Who else touches your data? The full subprocessor list.

The complete list, including the two transfers outside the EU.

CompanyPurposeData involvedLocation
VercelApplication hostingApplication requests and responsesFunction region fra1 — Frankfurt, EU
SupabaseDatabase, authentication and file storageRegister records, user accounts, uploaded evidence fileseu-central-1 — Frankfurt, EU
BrevoTransactional emailEmail address, name, message contentEU
Google AnalyticsProduct analytics on the marketing siteMarketing-site usage dataUnited States — a transfer outside the EU
AnthropicDrafting market-sensing commentary — Assure tier onlyAnonymised posture summary: vendors, classification outcomes, autonomy levels, definition status, counts and matched signals. No organisation name, personal names or customer contentUnited States. No training on API data; outbound payload anonymised.

The Anthropic call carries an anonymised summary and applies to the Assure tier only. It contains no organisation name, no company number, no personal names, no user email addresses and none of the content your registered AI systems process. What it does carry is the shape of the estate: vendors, classification outcomes, autonomy levels, definition status and counts. Anthropic does not train models on data submitted through its API. Assure customers who would rather the feature were switched off entirely can ask us to disable it on their account.

What is not in place yet? The security roadmap.

The baseline above is in place today on every plan. The work below is committed and in progress. We publish it because a buyer evaluating a governance product should be able to see the plan, and because this page is where each item will be marked done. We will not date an item until we can stand behind the date.

An independent penetration test

ISO/IEC 27001 or SOC 2 certification

Enforced multi-factor authentication

SSO for Assure customers

Formal periodic access reviews

Published backup and recovery commitments

Is ISO/IEC 42001 an information-security certification? No.

ISO/IEC 42001 is a management-system standard for artificial intelligence. It is not ISO/IEC 27001, and it says nothing about information security. The two are routinely conflated.

Using AI Register does not confer any certification on your organisation, under 42001 or any other standard. The product keeps the record; the certification, if you want one, is a separate exercise with an accredited body.

We say this from inside the standard rather than outside it. Acuity’s assurance work is led by a certified ISO/IEC 42001 Lead Auditor. That is a credential held by a person, not a certification held by this product or by your organisation, and we are careful about the difference.

Ask us the awkward one.

Security questionnaires, subprocessor queries and vulnerability reports go to one address.

The mailbox is monitored during business hours, Irish time.