Security, and independence.
An assurance product is only as trustworthy as the way it handles the evidence behind it — and the distance it keeps from the systems it assesses. Here is how AIssure does both.
Where your evidence lives
Evidence files are stored in EU-region object storage (Hetzner, Falkenstein, Germany). Uploads go directly to storage over encrypted connections using short-lived, pre-signed URLs — so a file does not sit in an intermediate processing tier on its way in or out. Downloads are granted the same way: time-limited and scoped to the specific file.
Who can see it
Data is isolated per client organisation. Within your organisation, access is limited to your engagement team and the authorised poview.ai operators who run or support the assessment; client-portal users see their own organisation's data only. We are deliberate about this rather than absolute-sounding: operating an engagement requires named operators to have scoped access, and we would rather describe that plainly than imply an isolation model we do not run.
We don't train on your evidence
Your evidence exists to produce your assessment — nothing else. It is not folded into the shared regulatory knowledge graph, and it is not used to train or fine-tune models. The graph is built from public primary regulatory text; your documents stay on your side of that line.
Independence by design
The most important security property AIssure has is not a control — it is a boundary. AIssure attests to your AI governance; it never operates, monitors or supplies the systems it assesses. That separation is what lets the opinion mean something: a party that ran your controls could not objectively assure them. We consume the evidence your monitoring produces; we do not become the monitoring.
Findings you can re-perform
A finding published today should still stand at an inspection next year. AIssure renders its published findings through a pinned, deterministic configuration, so a citation-grade opinion can be reproduced and defended later, rather than quietly shifting because an underlying model was retired or re-tuned.
Access & authentication
The platform uses role-based access — separate consultant, administrator and read-only client-portal roles — over authenticated, encrypted sessions. Sign-in is federated; subsequent access runs on a server-side session bound to the resolved user and role, on the principle of least privilege.
AIssure is a poview.ai platform. Data-handling specifics for the public site are in the Privacy Policy; questions about a specific engagement's controls are best answered directly — info@aissure.app.
Related
The regulatory knowledge graph
Built from public primary text — not your data.
→ ProcessHow an engagement runs
What we ask for, and what we do with it.
→ The categoryThe AI governance audit
Why independence sits at the centre of the product.
→ LegalPrivacy Policy
How personal data is handled on this site.
→Security & independence — the questions we get.
What risk, security and procurement teams ask before they share evidence.
Where is our evidence stored?
In EU-region object storage (Hetzner, Falkenstein, Germany). Files are uploaded directly to storage over encrypted connections using short-lived, pre-signed URLs, so evidence does not pass through a third-party processing layer.
Do you train models on our evidence?
No. Your evidence is used to produce your assessment. It is not folded into the shared regulatory knowledge graph and is not used to train models — the graph is built from public primary regulatory text, not client data.
Who can access our engagement?
Access is scoped per client organisation. Within that, it is limited to your engagement team and the authorised poview.ai operators running or supporting the assessment. Client-portal users see their own organisation's data only.
Why don't you also monitor our models?
Because independence is the point. AIssure forms an opinion over your AI governance; a party that also operated or monitored your models could not objectively attest to them. We consume your monitoring evidence — we do not produce it.
Start with a thirty-minute read on your readiness.
A high-level, question-only session — 12 to 16 questions, no evidence to prepare — for an initial view of your AI governance maturity and readiness. It sets the scene for a full engagement: the audit platform deployed and evidence-based assessments run, self-serve or consultant-supported.