Trust Center
How ai42001.ai handles your data
This platform is operated by an ISO/IEC 42001 Lead Auditor. The same discipline we assess in your AI management system governs how we treat your data: collect the minimum, keep it in one place, delete it on schedule — and be able to prove it.
We assess readiness. We do not issue certification. Certification audits are performed by independent certification bodies, separately from this platform. Our assessment has no commercial stake in whether you pass — which is exactly how an assessment should work.
01 · Data-minimal by design
We ask for as little as possible
The less of your data we hold, the less you have to trust us with. That is a design decision, not an accident.
Free assessment: nothing to upload
The Tier 1 readiness assessment requires no account and no documents. Try the platform before you share anything.
Evidence upload is optional
The full 209-question expert assessment can be completed on self-attestation alone. Evidence files add depth to the analyst review, but they are never required.
Masked excerpts, never originals
If you do upload evidence, we ask for redacted excerpts. Do not upload live credentials, secrets, or personal data of third parties — a masked policy page or screenshot is enough.
Payments never touch our systems
Paddle is our merchant of record. Your card details are processed entirely by Paddle and never reach ai42001.ai infrastructure.
02 · Storage & security
Where your data lives
All assessment data — answers, evidence files, and contact details — is stored in the European Union (Frankfurt, eu-central-1). Data is encrypted in transit (TLS 1.2 or higher) and at rest. Evidence files are held in a private storage bucket: there are no public links, and access requires a signed, time-limited URL issued only to the assigned analyst.
The site enforces HSTS, a strict Content-Security-Policy, and related security headers. Security researchers can find our disclosure channel at /.well-known/security.txt.
03 · Retention & automatic deletion
Your data is deleted on a schedule, not on request
You do not need to ask us to delete your data. Deletion is executed automatically by a scheduled job that runs every day — it does not depend on anyone remembering to do it.
ASSESSMENTS
SESSIONS
04 · The deletion certificate
Deletion you can prove — without us keeping anything about you
When your data is deleted, the system issues a deletion certificate. The certificate record contains no personal data whatsoever — only the certificate ID, a pseudonymous session reference, the deletion timestamp, and counts of what was removed. Because it identifies no one, we can retain it indefinitely as proof of deletion.
Certificate ID — specimen
AI42-DEL-20260713-c1753b42
AI42-DEL
Fixed prefix: a deletion certificate issued by ai42001.ai
20260713
The date the deletion was executed (UTC)
c1753b42
Pseudonymous session reference — a random identifier that names no person or company
Why we cannot send it to you automatically: your contact details are deleted together with everything else. Once the deletion runs, there is no email address left in our systems to send the certificate to. That is not a limitation — it is the proof that the deletion is real.
How to request your certificate at any time:
- Email tier2@ai42001.ai and attach your Paddle order receipt (it shows your order number). The receipt is your proof of purchase — only the genuine buyer has it.
- We match the order number to the assessment session and reply with your deletion certificate, typically within 3 business days.
- Your request email — including your address — is deleted within 90 days of the request being resolved. We do not re-build a record of you in the process.
05 · Subprocessors
Who else touches your data
We keep the list short. These are the services that process data on our behalf, and what each one does:
| Service | Role | Data location |
|---|---|---|
| Supabase | Assessment database, evidence storage, backend functions | EU — Frankfurt (eu-central-1) |
| Kinsta | Website hosting (marketing site) | Tokyo, Japan |
| Cloudflare | CDN and TLS termination | Global edge network |
| Paddle | Payments — merchant of record; card data is handled solely by Paddle | United Kingdom |
| Resend | Transactional email delivery | United States |
| Google Workspace | Business email for support and certificate requests | Global |
06 · Questions
Talk to the person who built this
Deletion certificates & assessment data: tier2@ai42001.ai
Security disclosures: security@ai42001.ai · security.txt
Full details: Privacy Policy · Terms of Service