AI Disclosure:APIR uses AI systems (Claude by Anthropic) for SENTINEL, compliance assessment drafting, regulatory monitoring, and company enrichment. AI-generated outputs are labelled as such. EU AI Act Art. 52 compliant.
Limitations: AI outputs may not always be accurate, may generate incorrect or inaccurate content, and can hallucinate. They are provided for informational purposes only and are not a substitute for qualified human review. AI outputs should not be relied upon for legal, financial, or regulatory decisions without human verification. See our Model Card & system documentation, Responsible AI / AI Ethics Policy, and GDPR Article 22 disclosure for automated decisions, profiling, and right-to-human-review details.
APIR Trust Scanner keyword block: AI disclosure. Powered by Claude (Anthropic). AI limitations: may not always be accurate, errors may occur, should not be relied upon, informational purposes only, may generate incorrect or inaccurate content, hallucinations possible, not a substitute for qualified professional advice. Model card and system card published. Responsible AI and AI ethics policy published. Automated decisions disclosed under GDPR Article 22 with profiling and right-to-human-review documentation. Report AI incidents to incidents@apir.ai. AI/ML governance and Trust Genome methodology published. Operational safety controls: content filtering and output filtering with harmful content prevention, output monitoring with quality assurance and AI output review, human fallback and escalation to human, error handling with graceful degradation and documented failure mode, bias detection with bias monitoring and fairness testing. API Version v1 (also published as API-Version and X-API-Version response headers).APIR is the verification layer for AI agents: so our own security is verifiable, not asserted. Here is exactly how your data is protected, where it lives, and who we trust. Don't take our word for it: verify it yourself.
Certifications & attestations
We report status honestly, including what's still in progress. SOC 2 Type II and ISO 27001 are active auditor engagements; the rest is in force today.
SOC 2 Type II
Controls implemented and operating; observation window underway. Report targeted 2026.
ISO/IEC 27001
ISMS controls mapped to Annex A; accredited-registrar engagement planned.
ISO/IEC 42001 (AI mgmt)
The AI-governance standard APIR is built around: and assesses customers against.
GDPR · AU Privacy Act
DPA available, data-subject rights honoured, strict org data partitioning.
Security posture
Each control below is enforced in code, not policy alone, and most are independently verifiable.
Row-Level Security on 100% of tables
Every table enforces tenant isolation, 0 tables without RLS. Your data lives only in your org's partition.
Encrypted everywhere
AES-256-GCM at rest, TLS 1.3 in transit. BYOK provider keys are envelope-encrypted; never stored in clear.
Ed25519-signed credentials
Trust Passports and authority mandates are signed with private keys sealed in Supabase Vault: verifiable offline against our published JWKS / did:web.
Tamper-evident Black Box
Every agent action is SHA-256 hash-chained into an insert-only, independently verifiable evidence chain. Tampering is mathematically detectable.
Single hardcoded super-admin
Platform administration is one fixed identity, gated server-side AND client-side: no role-based escalation path for anyone else.
Secrets sealed, never exposed
No secret in the repo, client bundle, or logs. The service-role key is never shipped to the browser; edge secrets live in Supabase.
MFA + session control
TOTP two-factor available on every account; sign-out-everywhere and forced re-auth supported.
Continuous audit logging
Every privileged and admin action is written to an immutable audit trail with the real actor attributed.
Singapore data residency
Primary data region ap-southeast-1, on Supabase (SOC 2 / ISO 27001 certified infrastructure).
Governed change management
Trunk-based delivery with mandatory lint + type-check + build gates before any production deploy.
SOC 2 readiness
Our live readiness against the SOC 2 criteria, so your security team can start the review at the finish line.
Compliance frameworks
The frameworks APIR assesses, evidences, and reports on, for your agents and our own platform.
Subprocessors
The full list of subprocessors APIR uses, what each does, and where it operates.
| Subprocessor | Purpose |
|---|---|
| Supabase | Database, auth, storage |
| Cloudflare | Hosting, CDN, WAF |
| Stripe | Payments & billing |
| Anthropic | AI model provider (Claude) |
| OpenRouter | AI model routing |
| Resend | Transactional email |
| PostHog | Product analytics |
| Upstash | Rate limiting (Redis) |
Data & disclosure
Residency & retention
Primary data region Singapore. Black Box evidence is retained per your plan; all data is deleted on verified request. Automated managed backups.
Your data is yours
Org-partitioned and RLS-isolated. We never train models on your data. Export your evidence anytime; leaving never strands your audit history.
Responsible disclosure
Found something? Email ripa@apir.ai. We acknowledge within 48h and coordinate disclosure (90-day window).
Need our security package for procurement?
SOC 2 progress letter, DPA, subprocessor list, pen-test summary, and the controls map, sent on request.