Security
How we protect your data and our infrastructure.
Data Residency
Our infrastructure provider, Base44, operates data centers in the EU region. Seal verification data, assessment responses, and entity records are all stored in EU-based databases.
Encryption
Data is encrypted in transit using TLS 1.3 for all API calls, web traffic, and backend function invocations. Data is encrypted at rest using AES-256 as provided by our infrastructure layer. SHA-256 hashing is used for seal integrity. All API keys are stored as cryptographic hashes, never in plaintext. Webhook secrets are generated using cryptographically secure random generation and stored as hashes.
Access Controls
Access to production data is restricted to two authorized operators: Thomas Krojzl (primary) and Clare Blanchard (backup). Access is authenticated via Base44 platform credentials with two-factor authentication. Row-level security (RLS) ensures that user assessment data is only visible to the user who created it. Administrative access (service role) is used only by backend functions for seal verification and registry operations. All administrative actions are logged in the Admin Audit Trail with timestamp, actor, and severity.
Sub-Processors
We use the following sub-processors to deliver our service:
| Provider | Purpose | Location | Data Accessed |
|---|---|---|---|
| Base44 | Application hosting, database, backend functions | EU | Seal records, assessment data, entity records |
| Stripe | Payment processing | EU and US | Email, payment method, transaction amount |
| Groq | AI witness model (GPT-OSS-120B, Qwen3.6-27B) | US | Public website URLs and content only |
| Google AI Studio | AI witness model (Gemini 3.6 Flash) | Global | Public website URLs and content only |
| xAI | AI witness model (Grok 4.3) | US | Public website URLs and content only |
AI witness models only process publicly available website URLs. No personal data, assessment responses, or seal data is sent to AI providers.
Incident Response
Our incident response plan defines three severity levels: Critical (seal data compromised or verification system down), Warning (partial service degradation or API rate limiting), and Info (routine maintenance or non-critical updates). Critical incidents trigger immediate notification to both operators, a 72-hour assessment window per Article 73 of the EU AI Act, and public disclosure in the Admin Audit Trail. The full Incident Response Plan is published on our Compliance page.
Compliance & Standards
Proof of Operator is designed to map to the following frameworks:
- EU AI Act Article 14(4)(a)-(e): Human oversight requirements (mapped, not certified)
- GDPR Articles 17 and 20: Right to erasure and data portability (live endpoints)
- ISO 27001 controls (mapped, not certified)
- NIST AI Risk Management Framework (mapped, not certified)
Proof of Operator is not a regulatory certification body. Seals are evidence of operator assessment, not regulatory compliance. The methodology is publicly auditable.
Security Contact
To report a security vulnerability or request a security review, contact:
thomas@brainiaclimited.comWe acknowledge all security reports within 48 hours and provide a detailed response within 5 business days.