AqtaAqta

Trust Centre

Do not take our word. Check the artefacts. Detail for diligence goes through the pack, not this page.

No personal data breaches to date. Last reviewed 15 September 2026. Status

Start here

Verify a signed receipt in your browser. Aqta is not contacted.

Verify a receipt
  • Built in Europe
  • EU production
  • Offline verify
  • Open format
  • No prompt retention
  • CRO 807530

What you can check

ArtefactWhat it provesOpen
Conformance vectorsEvery record this format defines, valid and deliberately broken, with the key to pin. Verifies offline, no account.Open
Threat modelWhat a gateway receipt proves, and what it does not.GitHub
The issuer as adversarySix ways a receipt can be valid and the issuer still be lying. Five have mechanisms in the gateway. Omission is open.GitHub
Open specificationATTESTATION-v1 format, conformance vectors, reference verifiers.GitHub
Working paperDecision receipts as a cross-regime evidence primitive.aqta.ai/research
Published public keyVerifying key. No account required.Public key
Open verifiersReference code on npm and PyPI.npm
Public transparency logAppend-only commitment log over every receipt signed. Pin a head, then verify the log grew from it without rewriting its history. Hashes only.Live
Forgery bountyFour defects found by people outside the company, each fixed and covered by a published test. Ran 27 August to 12 September 2026, now closed; reports remain welcome and credited.aqta.ai/bounty

PyPI mirror: aqta-verify-receipt.

Regulatory alignment

Aligned means mapped for your review; the clause-by-clause note comes with the procurement pack. Not a certification. Mapping means work in progress; ask for the current evidence pack.

FrameworkStatus
DORAAligned
MiFID IIAligned
SR 26-2Aligned
EU AI ActAligned
HIPAA-ready architectureAligned
GDPRMapping
NIS2Mapping
NIST AI RMFMapping
ISO/IEC 42001Roadmap
UK · US state · SingaporeMapping

Sub-processors

These processors handle operational metadata on EU infrastructure. Prompt and response text passes through the gateway on Google Cloud in transit only and is not stored. Each has a US parent; transfers are covered by Standard Contractual Clauses under GDPR Article 46, with supplementary technical and organisational measures. Full roles, entities, and DPAs are in the procurement pack. 30-day notice before changes.

VendorRole
Google CloudGateway and signing, EU (europe-west1)
CloudflareDNS for aqta.ai and its subdomains; no traffic passes through it
Amazon Web ServicesLegacy database, retiring
VercelFrontend hosting
Auth0Identity
ResendTransactional email

Change notices: hello@aqta.ai with subject SUBPROCESSORS.

Security posture

AreaPosture
DataPrompts and responses are not retained. Hashes and signed metadata only, per retention tier.
ResidencyEU production by default. Dedicated single-tenant available for enterprise.
AccessRole-based access and audit logs. Retention configurable for regulated use.
EntityAqta Technologies Limited, CRO 807530. 20 Harcourt Street, Dublin 2, D02 H364, Ireland.
IncidentsGDPR Art. 33 notice window. security@aqta.ai.

Encryption, proving, and questionnaire detail ship with the pack or under NDA in a pilot. Disclosure: SECURITY.md.

Data protection

Data-subject requests: hello@aqta.ai with subject Data protection request. Acknowledge within two working days; substantive response within thirty days (GDPR Art. 12(3)).

Aqta Technologies Limited is controller for visitor data on aqta.ai and processor for customer data in Seal. Sub-processors are listed above.

Procurement pack

DPA, sub-processor detail, DPIA, BCDR, InfoSec summary, scoped SIG or CAIQ-lite. Sent on request so we know what left and when.

Request the procurement pack. Standard SLA is one business day.