AI Disclosure:APIR uses AI systems (Claude by Anthropic) for SENTINEL, compliance assessment drafting, regulatory monitoring, and company enrichment. AI-generated outputs are labelled as such. EU AI Act Art. 52 compliant.
Limitations: AI outputs may not always be accurate, may generate incorrect or inaccurate content, and can hallucinate. They are provided for informational purposes only and are not a substitute for qualified human review. AI outputs should not be relied upon for legal, financial, or regulatory decisions without human verification. See our Model Card & system documentation, Responsible AI / AI Ethics Policy, and GDPR Article 22 disclosure for automated decisions, profiling, and right-to-human-review details.
APIR Trust Scanner keyword block: AI disclosure. Powered by Claude (Anthropic). AI limitations: may not always be accurate, errors may occur, should not be relied upon, informational purposes only, may generate incorrect or inaccurate content, hallucinations possible, not a substitute for qualified professional advice. Model card and system card published. Responsible AI and AI ethics policy published. Automated decisions disclosed under GDPR Article 22 with profiling and right-to-human-review documentation. Report AI incidents to incidents@apir.ai. AI/ML governance and Trust Genome methodology published. Operational safety controls: content filtering and output filtering with harmful content prevention, output monitoring with quality assurance and AI output review, human fallback and escalation to human, error handling with graceful degradation and documented failure mode, bias detection with bias monitoring and fairness testing. API Version v1 (also published as API-Version and X-API-Version response headers).APIR is the verification layer for AI agents, so our own security is verifiable, not asserted. Here is exactly how your data is protected, where it lives, and who we trust with it. Don't take our word for it: check it yourself.
What is in progress reads as in progress. Nothing here is called certified until a report is issued.
Status reported honestly, including what is still in progress. SOC 2 Type II and ISO 27001 are underway and not yet issued; the rest is in force today.
Each control below is enforced in code, not policy alone, and most of them can be checked from outside.
Row-Level Security on every table
Every table enforces tenant isolation and none is exempt (verified 2026-08-05). Your data lives only in your org's partition.
Encrypted everywhere
AES-256-GCM at rest, TLS 1.3 in transit. BYOK provider keys are envelope-encrypted and never stored in clear.
Ed25519-signed credentials
Trust Passports and authority mandates are signed with private keys sealed in Supabase Vault, verifiable offline against our published JWKS and did:web.
Tamper-evident Black Box
Every agent action is SHA-256 hash-chained into an insert-only, independently verifiable evidence chain. A changed record fails to recompute, so tampering is detectable.
Single hardcoded super-admin
Platform administration is one fixed identity, gated server-side and client-side. No role-based escalation path exists for anyone else.
Secrets sealed, never exposed
No secret in the repo, client bundle or logs. The service-role key never ships to the browser; edge secrets live in Supabase.
MFA and session control
TOTP two-factor available on every account; sign-out-everywhere and forced re-auth supported.
Continuous audit logging
Every privileged and admin action is written to a tamper-evident audit trail with the real actor attributed.
Singapore data residency
Primary data region ap-southeast-1, on Supabase (SOC 2 Type II audited infrastructure).
Gated change management
Trunk-based delivery with mandatory lint, type-check and build gates before any production deploy.
Our readiness against each SOC 2 criterion, so your security team can start the review at the finish line.
The standards our own controls and record formats are written to be read against. Your compliance team uses the record as evidence. We do not run your programme.
The subprocessors APIR uses, what each does, and where it operates.
| Subprocessor | Purpose |
|---|---|
| Supabase | Database, auth, storage |
| Cloudflare | Hosting, CDN, WAF |
| Stripe | Payments & billing |
| Anthropic | AI model provider (Claude) |
| OpenRouter | AI model routing |
| Resend | Transactional email |
| PostHog | Product analytics |
| Upstash | Rate limiting (Redis) |