Trust & transparency.

AICVS is a compliance tool. The same standard we expect of customer documentation we apply to ourselves: factual, citable, falsifiable. Below is what we do, what we don't, what data we hold, and where it lives.

Official references and review cadence. We align mappings to official references and publish a date checked marker on this page. Guidance may evolve as regulators publish updates. AICVS provides readiness support based on available records; it is not legal advice and not legal certification.

Operating posture

Status
Operational
All systems green · checked hourly
Last incident
None reported
Public incident log on roadmap
Compute region
Frankfurt (DE)
Primary AICVS API compute. Other subprocessors are listed below and are not all EU-only.
Database region
EU-West-1 (IE)
Supabase · AWS Dublin
Supervisory authority
Irish DPC
Data Protection Commission · Dublin
Patent status
Application filed
IPOI · pending grant · do not assume protection until granted

What AICVS does and does not do

The risk in compliance tooling is overclaim. We treat the boundary explicitly because regulators read marketing copy and so do compliance officers.

Does

Does not

Data we hold for each scan

The single most important commitment we make to subscribers is what happens to your source code. Every scan operates as follows:

One caveat we want you to know about. Filenames you submit can sometimes contain personal data (e.g. a developer's name in a path: /Users/john_smith/repo/file.py). Filenames are sanitised at upload to strip leading paths, but the basename is stored. Where possible, submit non-sensitive filenames. The Privacy Notice explains the legal basis and data subject rights in detail.

For a live machine-readable view of what we hold per scan, see https://api.aicvs.io/api/v1/transparency/data-flow.

Data retention

Subprocessors

We keep the stack deliberately small so export, deletion, and incident response are practical for a small team.

Availability & disaster recovery

We are honest about our stage: AICVS is operated by a small team and does not offer a contractual uptime SLA on public self-serve plans. What we do commit to:

Enterprise customers who need defined RTO/RPO targets, a signed SLA, or a formal DPA can request these during procurement — see the Enterprise plan.

Customer export and offboarding

If a customer asks to leave, we can prepare an export of organisation records and run an erasure workflow. The export may include account/team records, AI inventory, role profile, risk classifications, suggested controls, evidence metadata, vendor records, monitoring plans, incident records, generated policies, technical documentation, scan findings, hashes, timestamps, reports, and audit-pack records.

Deletion is handled with a dry-run-first internal tool and a confirmation step. Some records may be retained where required for tax, billing, security, fraud prevention, legal dispute handling, backup expiry, or historical evidence verification. Where something cannot be deleted immediately, we explain why and for how long.

Continuity — what happens to your evidence if we don't survive

We are a small company, and compliance is a multi-year commitment. “What happens to my evidence if you stop trading?” is a reasonable question to ask us and an uncomfortable one to answer, so here is the answer in writing rather than on request.

What we are not claiming: this is a published commitment, not an escrow arrangement or a bank guarantee, and a company that has ceased trading cannot honour a notice period retroactively. The part that genuinely survives us is the third bullet — a certificate anyone can verify offline, forever, using code we do not control.

Verification & transparency endpoints

We expose a small number of public endpoints designed to let you verify the claims on this page without contacting us:

The /verify endpoint recomputes the evidence chain and reports what actually matched; it does not simply confirm that a record exists.

Frameworks & their honest status

What we are not

We are an early-stage Irish company with a focused product. We are not a multinational consulting firm. We do not have a public list of Fortune 500 customers. We do not publish testimonials we cannot verify. The right comparison for AICVS is the toolchain a competent compliance officer would build for themselves if they had unlimited time. We compress that build time into a subscription.

Reporting a security issue

If you believe you have found a security vulnerability, email security@aicvs.io. Use our PGP key from /.well-known/security.txt for sensitive details. We acknowledge within 48 hours and aim to resolve critical issues within 7 days. We do not currently run a paid bounty programme but we do credit reporters publicly with permission.

Talking to us

The fastest way to evaluate whether AICVS is right for your team is to run a free scan on a real file from your codebase. The next-fastest is our contact form (topic + consent) or an email to hello@aicvs.io with a description of your stack, your AI Act exposure, and any specific concerns. We answer in business hours, Irish time, with a human.

Last reviewed: 5 August 2026 · Next review: 5 November 2026 ·Page maintained by the team at Rivoryn Limited.