SECURITY

Security

How we protect your data and our infrastructure.

DATA RESIDENCY

Data Residency

Our infrastructure provider, Base44, operates data centers in the EU region. Seal verification data, assessment responses, and entity records are all stored in EU-based databases.

ENCRYPTION

Encryption

Data is encrypted in transit using TLS 1.3 for all API calls, web traffic, and backend function invocations. Data is encrypted at rest using AES-256 as provided by our infrastructure layer. SHA-256 hashing is used for seal integrity. All API keys are stored as cryptographic hashes, never in plaintext. Webhook secrets are generated using cryptographically secure random generation and stored as hashes.

ACCESS CONTROLS

Access Controls

Access to production data is restricted to two authorized operators: Thomas Krojzl (primary) and Clare Blanchard (backup). Access is authenticated via Base44 platform credentials with two-factor authentication. Row-level security (RLS) ensures that user assessment data is only visible to the user who created it. Administrative access (service role) is used only by backend functions for seal verification and registry operations. All administrative actions are logged in the Admin Audit Trail with timestamp, actor, and severity.

SUB-PROCESSORS

Sub-Processors

We use the following sub-processors to deliver our service:

ProviderPurposeLocationData Accessed
Base44Application hosting, database, backend functionsEUSeal records, assessment data, entity records
StripePayment processingEU and USEmail, payment method, transaction amount
GroqAI witness model (GPT-OSS-120B, Qwen3.6-27B)USPublic website URLs and content only
Google AI StudioAI witness model (Gemini 3.6 Flash)GlobalPublic website URLs and content only
xAIAI witness model (Grok 4.3)USPublic website URLs and content only

AI witness models only process publicly available website URLs. No personal data, assessment responses, or seal data is sent to AI providers.

INCIDENT RESPONSE

Incident Response

Our incident response plan defines three severity levels: Critical (seal data compromised or verification system down), Warning (partial service degradation or API rate limiting), and Info (routine maintenance or non-critical updates). Critical incidents trigger immediate notification to both operators, a 72-hour assessment window per Article 73 of the EU AI Act, and public disclosure in the Admin Audit Trail. The full Incident Response Plan is published on our Compliance page.

COMPLIANCE & STANDARDS

Compliance & Standards

Proof of Operator is designed to map to the following frameworks:

  • EU AI Act Article 14(4)(a)-(e): Human oversight requirements (mapped, not certified)
  • GDPR Articles 17 and 20: Right to erasure and data portability (live endpoints)
  • ISO 27001 controls (mapped, not certified)
  • NIST AI Risk Management Framework (mapped, not certified)

Proof of Operator is not a regulatory certification body. Seals are evidence of operator assessment, not regulatory compliance. The methodology is publicly auditable.

SECURITY CONTACT

Security Contact

To report a security vulnerability or request a security review, contact:

thomas@brainiaclimited.com

We acknowledge all security reports within 48 hours and provide a detailed response within 5 business days.

Brainiac Ltd - 167-169 Great Portland Street, London, W1W 5PF
© 2026 Brainiac Ltd. All rights reserved.

Brainiac Ltd is registered in England and Wales. Operating from Prague, Czech Republic. Proof of Operator is an independent AI oversight verification tool. Seals are not regulatory certifications. All methodology is publicly auditable.

Brainiac Ltd. Make your Presence felt.