Security & Privacy โ€” Stack of Truths | EU AI Act Compliant

Security & Privacy โœ“ EU AI Act Compliant โœ“ GDPR Compliant

Last updated: May 13, 2026

At Stack of Truths, I take security seriously โ€” not just for my clients, but for their customers too. This page explains how I protect your data, maintain confidentiality, and ensure every report is verifiably authentic. Based in The Netherlands ๐Ÿ‡ณ๐Ÿ‡ฑ

๐Ÿ” AES-256-CBC + PBKDF2

Your data is encrypted using the same standard as banks and governments.

๐Ÿ‡ช๐Ÿ‡บ EU AI ACT COMPLIANCE

Stack of Truths operates in full compliance with the European Union Artificial Intelligence Act (Regulation (EU) 2024/1689). As an AI security testing provider based in The Netherlands, we adhere to:

  • High-risk AI system conformity assessment (Article 43)
  • Transparency obligations for AI systems (Article 13)
  • Human oversight requirements (Article 14)
  • Robustness, accuracy, and cybersecurity standards (Article 15)

Our AI penetration testing reports can be used as evidence of compliance for clients deploying high-risk AI systems.

๐Ÿ“„ Report Security โ€” Complete

Every client receives a tamper-proof, verifiable report package. No one can fabricate a Stack of Truths report โ€” the GPG signature and hash verification make it mathematically provable.

๐Ÿ“ What clients receive:

report.html โ† Original HTML report

report.pdf โ† Branded PDF with watermark on every page

report.pdf.asc โ† GPG digital signature

๐Ÿ”‘ How clients verify authenticity:

# 1. Download public key curl https://stackoftruths.com/stackoftruths_pub.asc # 2. Verify GPG signature gpg –verify report.pdf.asc report.pdf # Output: Good signature from “Stack of Truths Security” # 3. Check SHA-256 hash sha256sum report.pdf # 4. Compare against verification API curl https://stackoftruths.com/api/verify/<REPORT_ID>

โœ… Compliance & Assurance

AuthenticityGPG signature โ€” proves report came from Stack of Truths
IntegritySHA-256 hash โ€” proves report wasn’t modified
Non-repudiationGPG key tied to Stack of Truths identity
WatermarkDiagonal “STACK OF TRUTHS CONFIDENTIAL” on every PDF page
VerificationPublic API endpoint + public key download

๐Ÿ“‹ Data Encryption at Rest

All client booking information, target domains, and audit data are encrypted immediately upon submission using:

  • AES-256-CBC โ€” Military-grade encryption algorithm
  • PBKDF2 โ€” Key derivation with 100,000 iterations
  • Unique passphrase โ€” Stored with 600 permissions (owner-only access)
openssl enc -aes-256-cbc -salt -pbkdf2 -iter 100000 \ -in client_data.json \ -out client_data.json.enc

๐Ÿ”’ Confidentiality & Non-Disclosure

Every client engagement is protected by a strict confidentiality agreement. I do not share findings, reports, or client identities without explicit written permission.

If you require a signed NDA before discussing your project, just ask โ€” I provide one for every engagement.

๐Ÿ›ก๏ธ Secure Pentesting Environment

All security assessments are performed on a dedicated, isolated pentest laptop:

  • No cross-contamination with production systems
  • Air-gapped where required
  • Tailscale VPN for secure remote access
  • UFW firewall with strict port rules
  • SSH with 2FA (Google Authenticator)

๐Ÿ“ Data Retention & Deletion

Client data is retained only as long as necessary:

30-90 daysAudit reports and findings
7 yearsInvoices (tax/legal requirement)
On requestFull data deletion

You may request deletion of your data at any time. I will confirm deletion within 72 hours.

๐Ÿ” Infrastructure Security

Your data resides on a VPS with the following protections:

  • โœ… Daily automated backups
  • โœ… Firewall (UFW) with minimal open ports (22, 80, 443, 8081, 8090)
  • โœ… Tailscale mesh VPN for authorized access only
  • โœ… SSH key + 2FA authentication
  • โœ… Regular security updates and patching

๐Ÿ“ง What Information We Collect

When you book a pentest, we collect:

  • Your name, email, and company (for engagement purposes)
  • Target domains or IP addresses (for testing)
  • Digital signature authorization (for legal compliance)
  • Payment information (processed securely via Stripe โ€” we never store your card details)

๐Ÿ”“ Your Rights (GDPR & EU AI Act)

Under GDPR (Regulation (EU) 2016/679) and the EU AI Act, you have the right to:

  • Access โ€” Request a copy of your data
  • Correct โ€” Update inaccurate information
  • Delete โ€” Request removal of your data (right to be forgotten)
  • Portability โ€” Receive your data in a structured format
  • Object โ€” Object to processing of your data
  • Human review โ€” Request human oversight of AI-based decisions

For privacy requests, DM @StackOfTruths on X or email pedrojose@stackoftruths.com. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

๐Ÿ“ž Contact Us

If you have any security concerns or privacy questions:


๐Ÿฆž Stack of Truths โ€” Website & AI Penetration Testing for Small Entrepreneurs
KVK 94992266 ยท Registered in Amsterdam, Netherlands ยท EU AI Act Compliant

Oh hi there ๐Ÿ‘‹
Itโ€™s nice to meet you.

Sign up to receive awesome content in your inbox, every month.

We donโ€™t spam! Read our privacy policy for more info.

You cannot copy content of this page

Follow by Email
YouTube
YouTube
LinkedIn
LinkedIn
Share