What you can check
Public proof only. Architecture and questionnaires stay in the pack.
| Artefact | What it proves | Open |
|---|---|---|
| Conformance vectors | Every record this format defines, valid and deliberately broken, with the key to pin. Verifies offline, no account. | Open |
| Threat model | What a gateway receipt proves, and what it does not. | GitHub |
| Open specification | ATTESTATION-v1 format, conformance vectors, reference verifiers. | GitHub |
| Working paper | Decision receipts as a cross-regime evidence primitive. | aqta.ai/research |
| Browser verify | Check a sample or paste a receipt. Runs locally. | aqta.ai/verify |
| Published public key | Verifying key. No account required. | Public key |
| Open verifiers | Reference code on npm and PyPI. | npm |
PyPI mirror: aqta-verify-receipt.
Regulatory alignment
Aligned means mapped for your review, with a public clause-to-field note linked from the row. Not a certification. Mapping means work in progress; ask for the current evidence pack.
| Framework | Status |
|---|---|
| DORA | Aligned |
| MiFID II | Aligned |
| SR 26-2 | Aligned |
| EU AI Act | Aligned |
| HIPAA-ready architecture | Aligned |
| GDPR | Mapping |
| NIS2 | Mapping |
| NIST AI RMF | Mapping |
| ISO/IEC 42001 | Roadmap |
| UK · US state · Singapore | Mapping |
Sub-processors
Three processors handle operational metadata on EU infrastructure. None receive prompt or response text. Each has a US parent; transfers are covered by Standard Contractual Clauses under GDPR Article 46, with supplementary technical and organisational measures. Full roles, entities, and DPAs are in the procurement pack. 30-day notice before changes.
| Vendor | Role |
|---|---|
| Google Cloud | Gateway and signing, EU (europe-west1) |
| Amazon Web Services | Legacy database, retiring |
| Vercel | Frontend hosting |
| Auth0 | Identity |
Change notices: hello@aqta.ai with subject SUBPROCESSORS.
Security posture
| Area | Posture |
|---|---|
| Data | Prompts and responses are not retained. Hashes and signed metadata only, per retention tier. |
| Residency | EU production by default. Dedicated single-tenant available for enterprise. |
| Access | Role-based access, MFA, audit logs. Retention configurable for regulated use. |
| Entity | Aqta Technologies Limited, CRO 807530. 20 Harcourt Street, Dublin 2, D02 H364, Ireland. |
| Incidents | GDPR Art. 33 notice window. security@aqta.ai. No incidents to date. |
Encryption, proving, and questionnaire detail ship with the pack or under NDA in a pilot. Disclosure: SECURITY.md.
Data protection
Data-subject requests: hello@aqta.ai with subject Data protection request. Acknowledge within two working days; substantive response within thirty days (GDPR Art. 12(3)).
Aqta Technologies Limited is controller for visitor data on aqta.ai and processor for customer data in Seal. Sub-processors are listed above.
Procurement pack
DPA, sub-processor detail, DPIA, BCDR, InfoSec summary, scoped SIG or CAIQ-lite. Sent on request so we know what left and when.
Request the procurement pack. Standard SLA is one business day.