Evidence Handling Policy

Last updated: 15 July 2026 Owner: Sang-Rok Yeo, Lead Auditor & Founder Operating Entity: ITG insights Co., Ltd. Primary data location: Supabase (EU / Frankfurt region)

Plain-language summary

You do not need to upload any documents to get a complete ai42001.ai Tier 2 Expert Assessment. Sharing evidence is entirely optional. If you do share, we limit access to one Lead Auditor, store it encrypted in the EU (Frankfurt), delete it automatically within about 51 days of your submission, and record a signed deletion certificate for the engagement. We never use it to train AI models or share it with anyone else. This policy explains how we do this in detail.

1. Purpose and scope

This policy describes how ai42001.ai handles any documents, screenshots, excerpts, or other materials (“evidence”) that clients voluntarily share during a Tier 2 Expert Assessment. It applies to all Tier 2 engagements globally. It does not apply to Tier 1 Free Assessments, which do not involve any document sharing.

2. Default position: evidence is not required

Tier 2 assessments are delivered primarily through a structured questionnaire covering the ISO/IEC 42001 clauses and Annex A controls. Clients are never required to upload or share any documents to receive a complete assessment, report, and expert review. This approach reflects how formal ISO/IEC 17021-1 certification audits operate in practice: through structured inquiry, observation, and dialogue — not bulk document collection.

3. Optional evidence sharing

Clients may voluntarily share evidence to upgrade specific findings from “self-reported” to “verified” in their assessment report. Verified findings carry higher confidence in benchmarking and may be referenced when preparing for formal certification. 3.1 What clients may share
  • Excerpts from policies, procedures, or risk assessments
  • Screenshots of system configurations, dashboards, or training records
  • Redacted sections of documents relevant to specific ISO/IEC 42001 controls
  • Summary descriptions of evidence in lieu of source documents
3.2 What clients should not share
  • Personal data of employees, customers, or third parties (names, contact details, identifiers)
  • Confidential commercial information (pricing, contracts, M&A plans)
  • Source code, model weights, training data samples, or proprietary algorithms
  • Trade secrets, intellectual property identifiers, or authentication credentials
If a client is uncertain whether material is appropriate to share, they should not share it. The assessment can be completed in full without that evidence.

4. Transmission

Evidence is transmitted through encrypted channels (TLS) to private storage hosted on Supabase (EU / Frankfurt region). Evidence is not accepted via email, instant messaging, or third-party file-sharing services.

5. Storage and access

Stored evidence is held in an isolated, private storage bucket and is encrypted at rest. Access is restricted to the Lead Auditor assigned to the engagement, who retrieves files only through short-lived, expiring download links. No third-party processors, subcontractors, or AI training systems have access to client evidence.

6. Retention period

Evidence is retained only as long as needed to deliver the assessment and support the engagement:
  • On submission of the assessment, a deletion date is set automatically for 51 days later. This window covers the expert review, report delivery, and any follow-up or re-opening of the assessment for revision.
  • If an assessment is re-opened for the client to revise their responses or evidence, the deletion clock is reset and re-applied (51 days) when the assessment is re-submitted.
  • If an assessment is never submitted, the client’s access link expires 30 days after it is issued, and the associated evidence and personal data are erased automatically shortly afterwards.
Clients may request earlier deletion at any time by contacting the assigned Lead Auditor.

7. Deletion

At the end of the retention period, deletion is performed automatically by a scheduled process. Evidence files are removed from storage, the corresponding evidence records are deleted from the database, and identifying personal data is erased. Anonymized questionnaire responses and computed benchmark values may be retained (see Section 10); they do not identify the client.

8. Deletion record and certificate

When evidence and personal data are erased, ai42001.ai generates a deletion record for the engagement. The record includes:
  • A unique deletion certificate identifier (format: AI42-DEL-YYYYMMDD-XXXXXXXX)
  • The session/engagement reference
  • The date of deletion
  • A count of the evidence items and records removed
  • Confirmation that identifying personal data was erased
This record is written to the engagement audit log, and a deletion summary is issued to the Lead Auditor. A signed certificate confirming these details is available to the client on request. To request the certificate, email tier2@ai42001.ai with your assessment reference (issued at submission) and/or your order receipt — see the Trust Center for details. Where no evidence was shared, the record confirms that no evidence was received and that the assessment data was handled under the same retention and deletion standards.

9. What ai42001.ai will not do

We will not:
  • use client evidence to train, fine-tune, or evaluate AI models;
  • share client evidence with any third party, including affiliated entities, without explicit written client authorization;
  • retain client evidence beyond the stated retention period;
  • access client evidence for any purpose other than delivering the contracted assessment.

10. Aggregated benchmarking data

ai42001.ai compiles aggregated, anonymized benchmarking statistics from assessment scores and metadata. Source evidence is never used in benchmarking — only structured questionnaire responses and computed scores. Aggregation occurs at a level that prevents identification of any individual client or organization, and is only shown where a sufficient number of comparable responses exists. This data underlies the global benchmark comparisons referenced in assessment reports.

11. Incident handling

If a confidentiality incident affecting client evidence occurs or is reasonably suspected, ai42001.ai will notify affected clients without undue delay, consistent with ISO/IEC 27001 incident management practice and applicable legal obligations.

12. Cross-border data transfer

Evidence is stored on infrastructure located in the European Union (Frankfurt). As ai42001.ai is operated from the Republic of Korea and uses providers in other countries, data may be transferred internationally. Where required, we rely on appropriate safeguards (such as standard contractual clauses). A Data Processing Addendum is available on request for clients requiring contractual safeguards.

13. Governance

This policy is operated under the ITG insights Co., Ltd. information security management system, aligned with ISO/IEC 27001. Related controls include:
  • A.5.20 Information security in supplier agreements
  • A.5.31 Legal, statutory, regulatory, and contractual requirements
  • A.5.34 Privacy and protection of personally identifiable information
  • A.8.10 Information deletion
  • A.8.24 Use of cryptography
This policy is reviewed at least annually, or whenever material changes are made to the Tier 2 service.

14. Contact

For questions about this policy, data subject requests, or evidence handling during a specific engagement: privacy@ai42001.ai This policy is owned by the Lead Auditor & Founder (Sang-Rok Yeo) and operated under the ITG insights Co., Ltd. information security management system.