Trust and Security
01 / 07

We don't sell promises. We provide proof.
Here is what you can check about us.

Where the data is stored, what leaves the perimeter and what doesn't, how evidence is protected and verified, and who is responsible. Written for the security manager, the data protection officer, and and legal counsel who have to sign off before the first call. If something isn't here, write to us and we'll publish it.

Data
02 / 07

Data residency, perimeter and outbound flows.

One design rule: the document doesn't travel. What leaves the perimeter is its fingerprint.

Residency

Data hosted in the European Union

The platform and its storage are hosted in data centers within the EU. There are no data transfers outside the EU for the operation of the service. Modules that use a language model do so through the provider configured by the customer, using the customer’s own account.

EU-hosted
Perimeter

The document never leaves your organisation

The cryptographic fingerprint is calculated where the file is located: in the Desktop Agent, in the Word Add-in, or on your own system via the API. What V-PROOF receives is the fingerprint and the compliance metadata, not the content.

The content never leaves
Verifiable evidence

Independent verification

The fingerprint and its metadata are linked to verifiable cryptographic evidence. A third party can verify the integrity and timestamp without a V-PROOF account and without accessing the client’s internal systems. The registry allows for subsequent verification of the accuracy and integrity of the recorded evidence. There are two ways to verify: by file, which calculates the fingerprint of a specific file and compares it to the recorded one; and by reference or V-Seal®, which queries the registry and displays what was recorded, but does not, on its own, prove that a specific file matches it.

Independent verification
Deployment
03 / 07

Two ways to deploy V-PROOF. In both cases, only the fingerprint travels outside.

01 · In your infrastructure

Installed in your cloud or on your servers.

Documents, data, and records remain within your organization. V-PROOF does not receive your content.

02 · Hosted by V-PROOF

We operate it ourselves on servers located in the EU.

We store only the cryptographic fingerprint of your documents. The content itself is not stored.

In both cases

The only evidence that is recorded is the fingerprint.

The auditor verifies it using the fingerprint alone, without accessing your platform or systems.

Intellectual Property and Trademarks →

Security
04 / 07

How we protect what we do handle.

Identity and Permissions
  • Distinct roles: administrator and user; only the administrator can synchronize, edit the control library, and create organizational connections.
  • Integration with Azure AD / Entra ID for corporate login.
  • Each approval step can only be decided by the person designated for that step.
Audit trail with no way to delete
  • Every governance action leaves an audit trail: who, when, what, before and after.
  • The app does not provide any way to edit or delete those rows, not even for an administrator.
  • Can be exported as a CSV file for an external auditor.
Encrypted credentials
  • Integration tokens are encrypted when saved and are not displayed again.
  • Code connections may be read-only.
  • Encryption in transit on all interfaces.
Compliance
05 / 07

Frameworks, certifications and current status.

We distinguish between the standards that the platform helps to meet and the certifications that V-PROOF holds as a company. They are not the same, and we do not confuse them.

Frame List How
EU AI Act (Regulation 2024/1689) Covered by the product Four-level classifier, 19 library controls, Article 12 record, human oversight under Article 14, FRIA under Article 27.
GDPR Covered by the product Legal basis by data asset, 11 controls, DPIA (Art. 35), safeguards (Art. 22).
ISO/IEC 42001 Covered by the product 22 controls of the AI management system in a library.
NIST AI RMF Covered by the product 19 controls in the library.
Internal Principles Covered by the product 5 controls related to the organization’s principles. A total of 76 controls in the library.
DORA · NIS2 · EU CRA Compliance Software lifecycle evidence and chain of custody for regulated entities.
ISO/IEC 27001:2022 · Information Security In the process of certification · 2026 Initial audit with OCA Global, a certification body accredited by ENAC.
ENS medium category · Royal Decree 311/2022 Under certification · 2026 Spain's National Security Framework (ENS), initial audit with OCA Global, an ENAC-accredited body. A requirement for providing services to the Spanish public sector.
ISO 9001:2015 · Quality Management In the process of certification · 2026 Initial audit with OCA Global, a certification body accredited by ENAC.

Scope of certification: the information systems that support the development and operation of the SaaS platform V-PROOF, for AI-assisted document management with cryptographic sealing and verifiable logging. We will publish each certificate, with its number, issuing body and scope, on the day it is issued. Until then, this table will read “under certification” and will not display any logos.

Procurement
06 / 07

Documents you can request today.

Data Protection

Data Processing Agreement (DPA). Available to customers and currently under review. Includes a list of subprocessors and their locations.

Upon request
Security

Technical description of the architecture. Workflow of the digital footprint from its origin through registration and verification, components deployable within your perimeter, and access matrix. For security reviews prior to contracting.

Upon request
Who is responsible?
07 / 07
Data Protection Officer

David Reifs

Data Protection Officer (DPO) appointed in accordance with Articles 37 through 39 of the GDPR.

david@vproof.io
Security Incidents

Reporting channel

To report a vulnerability or an incident. We respond to all reports.

david@vproof.io
Entity

V-PROOF PROTOCOL, S.L.

Vic, Barcelona · Spain. Data in Europe.

Legal Notice and Privacy Policy

See for yourself.

Any evidence issued by V-PROOF is verified on the public portal, without a V-PROOF account and without access to the client's internal systems.