Trust Centre

Do not take our word. Check the artefacts. Detail for diligence goes through the pack, not this page.

No incidents to date. Last reviewed 24 August 2026. Status

Start here

Verify a signed receipt in your browser. Aqta is not contacted.

Verify a receipt
  • Built in Europe
  • EU production
  • Offline verify
  • Open format
  • No prompt retention
  • CRO 807530

What you can check

Public proof only. Architecture and questionnaires stay in the pack.

ArtefactWhat it provesOpen
Conformance vectorsEvery record this format defines, valid and deliberately broken, with the key to pin. Verifies offline, no account.Open
Threat modelWhat a gateway receipt proves, and what it does not.GitHub
Open specificationATTESTATION-v1 format, conformance vectors, reference verifiers.GitHub
Working paperDecision receipts as a cross-regime evidence primitive.aqta.ai/research
Browser verifyCheck a sample or paste a receipt. Runs locally.aqta.ai/verify
Published public keyVerifying key. No account required.Public key
Open verifiersReference code on npm and PyPI.npm

PyPI mirror: aqta-verify-receipt.

Regulatory alignment

Aligned means mapped for your review, with a public clause-to-field note linked from the row. Not a certification. Mapping means work in progress; ask for the current evidence pack.

FrameworkStatus
DORAAligned
MiFID IIAligned
SR 26-2Aligned
EU AI ActAligned
HIPAA-ready architectureAligned
GDPRMapping
NIS2Mapping
NIST AI RMFMapping
ISO/IEC 42001Roadmap
UK · US state · SingaporeMapping

Sub-processors

Three processors handle operational metadata on EU infrastructure. None receive prompt or response text. Each has a US parent; transfers are covered by Standard Contractual Clauses under GDPR Article 46, with supplementary technical and organisational measures. Full roles, entities, and DPAs are in the procurement pack. 30-day notice before changes.

VendorRole
Google CloudGateway and signing, EU (europe-west1)
Amazon Web ServicesLegacy database, retiring
VercelFrontend hosting
Auth0Identity

Change notices: hello@aqta.ai with subject SUBPROCESSORS.

Security posture

AreaPosture
DataPrompts and responses are not retained. Hashes and signed metadata only, per retention tier.
ResidencyEU production by default. Dedicated single-tenant available for enterprise.
AccessRole-based access, MFA, audit logs. Retention configurable for regulated use.
EntityAqta Technologies Limited, CRO 807530. 20 Harcourt Street, Dublin 2, D02 H364, Ireland.
IncidentsGDPR Art. 33 notice window. security@aqta.ai. No incidents to date.

Encryption, proving, and questionnaire detail ship with the pack or under NDA in a pilot. Disclosure: SECURITY.md.

Data protection

Data-subject requests: hello@aqta.ai with subject Data protection request. Acknowledge within two working days; substantive response within thirty days (GDPR Art. 12(3)).

Aqta Technologies Limited is controller for visitor data on aqta.ai and processor for customer data in Seal. Sub-processors are listed above.

Procurement pack

DPA, sub-processor detail, DPIA, BCDR, InfoSec summary, scoped SIG or CAIQ-lite. Sent on request so we know what left and when.

Request the procurement pack. Standard SLA is one business day.