
Security Statement
Version 1.0-draft · Effective: [to be set at launch] · Reviewed every 6 months.
Our approach
Aequitas EU Market Passport handles sensitive business, legal, compliance and AI-system information. Security controls are designed accordingly and reviewed on a fixed schedule.
Technical controls
Encryption in transit (TLS 1.2+) and at rest; role-based access control with least privilege; admin access logging and audit trails; secure file upload with type validation and malware scanning [scanning provider placeholder]; rate limiting; session management with automatic expiry; backups with defined recovery objectives [RPO/RTO placeholder]; environment separation.
Organisational controls
Access reviews on a defined cadence; incident logging with severity classification; personal data breach procedure aligned with GDPR Arts. 33-34 (supervisory authority notification within 72 hours where required); vendor security assessment before onboarding subprocessors; the AI Vendor / LLM Provider Assessment Checklist applies to all AI subprocessors.
Reporting a vulnerability
See the Vulnerability Disclosure Policy at /legal/vulnerability-disclosure. We commit to acknowledgement within [x] business days and no legal action against good-faith research within policy scope.
Contact
office@digitalaequitas.ro.