Trust & Security

How we protect the data you trust us with.

ROPAi is a compliance tool. We treat the controls on our own platform the way we expect you to treat yours: documented, evidenced, reviewable.

● EU-hosted (Ireland) ● Encryption at rest and in transit ● 72-hour breach notification SLA ● ROPAi Ltd · Co. no. 17127400
Last reviewed: 26 April 2026 Need our DPA, sub-processor list, or security one-pager? Email [email protected]

At a glance

The shortest version of our security and trust posture. Each item is explained in detail below.

Data residency
EU (Ireland)
Primary data store hosted in Supabase EU-West. Customer data does not leave the EU for primary storage.
Encryption
At rest & in transit
AES-256 at rest. TLS 1.2+ in transit. Database access is authenticated and scoped per tenant.
Access model
Row-level isolation
Postgres Row Level Security enforces organisation boundaries. Roles mapped to organisation membership.
Breach notification
Within 72 hours
We will notify affected controllers within 72 hours of becoming aware of a confirmed personal data breach.
Data retention
Customer-controlled
You own your records. We retain data while your subscription is active and for a defined wind-down window after.
AI model
Claude (Anthropic)
Claude Sonnet for ROPA interviews, Claude Opus for legal drafting. No customer data is used to train models.

Hosting & infrastructure

ROPAi is a single-file web application backed by managed EU infrastructure. We have deliberately chosen a small, audited set of providers.

Primary components

  • Database & authentication: Supabase (Postgres + Auth + Storage), hosted in EU-West (Dublin, Ireland). All customer data is stored here.
  • Application hosting: Netlify, serving the web app and serverless functions used for checkout verification, billing portal generation, and DSAR intake analysis.
  • AI processing: Anthropic Claude API, called server-side. Prompts are transmitted over TLS; we use ephemeral prompt caching and we do not enable any training or data-sharing options on our account.
  • Payments: Stripe Checkout + Billing Portal. Card data never touches ROPAi systems. We store only the minimum Stripe customer and subscription identifiers needed to reconcile your plan.
  • Transactional email: Resend, used to notify a colleague that a DSAR query is waiting. The message carries no subject personal data, only the recipient's address and a secure link.

Provider assurance

We distinguish between the assurances held by our infrastructure providers and the certifications held by ROPAi itself. We do not present a provider's certification as if it were our own.

  • Current position: ROPAi is hosted on enterprise infrastructure providers including Supabase, Netlify, and Stripe. Those providers maintain their own security and compliance programmes, which form part of the control environment we rely on today.
  • What this means in practice: When a buyer asks about hosting assurance, we can point to the certifications and control posture of the platforms that store, authenticate, and serve customer data.
  • What we will not do: We will not describe ROPAi itself as ISO/IEC 27001 certified unless ROPAi Ltd has completed its own certification and external audit.
  • How we describe this externally: ROPAi currently relies on managed infrastructure with established security certifications while we build our own assurance programme and evaluate ISO/IEC 27001 as the business scales.

Sub-processors

Complete list of third parties that may process customer personal data on our behalf. We will notify customers of any material change at least 30 days before it takes effect.

Sub-processorPurposeData locationStatus
Supabase Inc.
Database, auth, storage
Primary data store for ROPA entries, DSAR cases, DPIA records, audit trail, organisation membership. Ireland (EU) Core
Netlify, Inc.
Web hosting & serverless
Static site delivery and Netlify Functions for Stripe verification, billing portal, and AI intake routing. EU region (edge) + US origin failover Core
Anthropic, PBC
Claude LLM API
AI-generated ROPA drafting, DPIA screening suggestions, and DSAR classification. Prompts are server-side only. United States (with SCCs & UK addendum) Core
Stripe Payments Europe Ltd.
Billing & payments
Subscription billing, checkout, and self-service customer portal. Card details handled by Stripe only. Ireland (EU) Core
Resend (Plus Five Five, Inc.)
Transactional email
Delivers DSAR colleague-query notifications. The email carries no subject personal data, only a recipient address and a secure link. The recipient's email address is the only personal data processed. United States (with SCCs & UK addendum) Core

Security controls

The controls we have in place today. We will publish our first independent audit on the roadmap below.

  • Encryption: AES-256 at rest across Supabase-managed storage. TLS 1.2+ for all traffic.
  • Tenant isolation: Postgres Row Level Security policies scope every query to the authenticated user's organisation membership. Cross-tenant reads are blocked at the database layer.
  • Authentication: Email magic link and email + password via Supabase Auth. Session JWTs are short-lived and rotated. SSO (SAML / OIDC) available on Enterprise plans (on the roadmap).
  • Soft deletes & audit: Records are soft-deleted with a deleted_at timestamp. Changes are written to an activity log for audit reconstruction.
  • Least privilege: A single team member has production database access. Production secrets are stored in Netlify env vars; never in source control.
  • Dependency hygiene: Dependabot enabled on both repositories. We avoid third-party JavaScript on customer-facing surfaces beyond core fonts.
  • Logging: Request and error logs are retained with access restricted to engineering. Logs exclude customer record content.
  • Backups: Supabase point-in-time recovery for the primary database. Full daily snapshots retained for 7 days on our current plan.

AI data handling

AI is useful for privacy teams only if you can defend how it processes your data. This is the posture.

What goes to the model

  • The ROPA interview sends the supplier name, purpose, and user-typed answers to Claude Sonnet to draft Article 30 fields.
  • The DSAR intake analyser sends user-pasted inbound email text to Claude to classify request type, extract requester details, and recommend a template.
  • The DPIA screening uses Claude Opus to suggest risks and mitigations based on the processing activity.

What we guarantee

  • No training on your data. We use Anthropic's API with no data-sharing or training options enabled. Anthropic's API terms confirm customer prompts are not used to train their models.
  • Server-side only. Prompts are sent from our Netlify Functions using our API key, never from the browser. No third-party AI script runs on the user's page.
  • No logging of prompt content beyond what is needed for error diagnosis. Request metadata is retained for up to 30 days.
  • Opt-out available. Customers on Govern and above can disable AI features entirely in Settings. The manual flows remain fully functional without AI.

Breach notification & incident response

The commitment we make to you as a controller.

  • 72-hour notification SLA. If we become aware of a confirmed personal data breach affecting your organisation, we will notify your named privacy contact within 72 hours.
  • What the notice contains. Nature of the breach, categories and approximate number of records affected, measures taken or proposed, and a direct contact for follow-up.
  • Incident log. All incidents, including near-misses that did not reach the notification threshold, are logged internally and reviewed quarterly.
  • Security contact: [email protected] for responsible disclosure, incident reports, and security questionnaires.

Your rights as a data subject

ROPAi is a processor for the customer data you upload to us. For your account data (your name, email, organisation), ROPAi Ltd is the controller. You can exercise your UK GDPR rights by emailing [email protected].

Need our DPA for vendor assessment?

We provide a Data Processing Agreement to every paying customer on request. Click below and we will send you the current template within one business day.

Request DPA →

Controller / company details