Security & Privacy โ EU AI Act Compliant โ GDPR Compliant
At Stack of Truths, I take security seriously โ not just for my clients, but for their customers too. This page explains how I protect your data, maintain confidentiality, and ensure every report is verifiably authentic. Based in The Netherlands ๐ณ๐ฑ
Your data is encrypted using the same standard as banks and governments.
๐ช๐บ EU AI ACT COMPLIANCE
Stack of Truths operates in full compliance with the European Union Artificial Intelligence Act (Regulation (EU) 2024/1689). As an AI security testing provider based in The Netherlands, we adhere to:
- High-risk AI system conformity assessment (Article 43)
- Transparency obligations for AI systems (Article 13)
- Human oversight requirements (Article 14)
- Robustness, accuracy, and cybersecurity standards (Article 15)
Our AI penetration testing reports can be used as evidence of compliance for clients deploying high-risk AI systems.
๐ Report Security โ Complete
Every client receives a tamper-proof, verifiable report package. No one can fabricate a Stack of Truths report โ the GPG signature and hash verification make it mathematically provable.
๐ What clients receive:
report.html โ Original HTML report
report.pdf โ Branded PDF with watermark on every page
report.pdf.asc โ GPG digital signature
๐ How clients verify authenticity:
โ Compliance & Assurance
| Authenticity | GPG signature โ proves report came from Stack of Truths |
| Integrity | SHA-256 hash โ proves report wasn’t modified |
| Non-repudiation | GPG key tied to Stack of Truths identity |
| Watermark | Diagonal “STACK OF TRUTHS CONFIDENTIAL” on every PDF page |
| Verification | Public API endpoint + public key download |
๐ Data Encryption at Rest
All client booking information, target domains, and audit data are encrypted immediately upon submission using:
- AES-256-CBC โ Military-grade encryption algorithm
- PBKDF2 โ Key derivation with 100,000 iterations
- Unique passphrase โ Stored with 600 permissions (owner-only access)
๐ Confidentiality & Non-Disclosure
Every client engagement is protected by a strict confidentiality agreement. I do not share findings, reports, or client identities without explicit written permission.
If you require a signed NDA before discussing your project, just ask โ I provide one for every engagement.
๐ก๏ธ Secure Pentesting Environment
All security assessments are performed on a dedicated, isolated pentest laptop:
- No cross-contamination with production systems
- Air-gapped where required
- Tailscale VPN for secure remote access
- UFW firewall with strict port rules
- SSH with 2FA (Google Authenticator)
๐ Data Retention & Deletion
Client data is retained only as long as necessary:
You may request deletion of your data at any time. I will confirm deletion within 72 hours.
๐ Infrastructure Security
Your data resides on a VPS with the following protections:
- โ Daily automated backups
- โ Firewall (UFW) with minimal open ports (22, 80, 443, 8081, 8090)
- โ Tailscale mesh VPN for authorized access only
- โ SSH key + 2FA authentication
- โ Regular security updates and patching
๐ง What Information We Collect
When you book a pentest, we collect:
- Your name, email, and company (for engagement purposes)
- Target domains or IP addresses (for testing)
- Digital signature authorization (for legal compliance)
- Payment information (processed securely via Stripe โ we never store your card details)
๐ Your Rights (GDPR & EU AI Act)
Under GDPR (Regulation (EU) 2016/679) and the EU AI Act, you have the right to:
- Access โ Request a copy of your data
- Correct โ Update inaccurate information
- Delete โ Request removal of your data (right to be forgotten)
- Portability โ Receive your data in a structured format
- Object โ Object to processing of your data
- Human review โ Request human oversight of AI-based decisions
For privacy requests, DM @StackOfTruths on X or email pedrojose@stackoftruths.com. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
๐ Contact Us
If you have any security concerns or privacy questions:
- ๐ฆ X (Twitter): @StackOfTruths
- ๐ง Email: pedrojose@stackoftruths.com
- ๐ Address: Keurenplein 41, 1069CD Amsterdam, Netherlands
๐ฆ Stack of Truths โ Website & AI Penetration Testing for Small Entrepreneurs
KVK 94992266 ยท Registered in Amsterdam, Netherlands ยท EU AI Act Compliant




