Start from what already works

AI Exchange Trust Center

What a reviewer can determine about AI Exchange.

This page is about the platform, not about any capability published on it. It answers the questions a security, privacy or procurement review brings, in plain language; behind each answer, one step deeper, are the statements it rests on and how each one is known. None of it is a certification, and no certification is claimed.

Independently certified
None claimed
Deeper assurance
On request
Last reviewed
2026-09-18

Security & AI Governance — Executive Summary

AI Exchange operates the platform through which organizations describe a need, find and evaluate reusable AI capability, and interact under governed workflows. This page states the platform’s security and governance posture at the level a security, privacy or procurement review needs first. The questions below carry the current facts, each with how it is known; deeper evidence is supplied on request.

  1. 01

    Trust boundary

    AI Exchange is responsible for the security and operation of the AI Exchange platform: its identity and authorization boundaries, its governed workflows, its evidence and publication controls, and the actions the platform performs. Responsibilities outside that platform boundary remain with the relevant participants unless AI Exchange explicitly assumes them under the applicable service or transaction terms.

  2. 02

    Security architecture

    Core data and model services are not directly exposed to the public Internet; the public boundary is served over HTTPS only. Workloads authenticate to platform infrastructure by identity rather than stored credentials. Each organization is an isolated authorization domain. Infrastructure is defined as code and released through a controlled process, and the deployed posture is checked against AI Exchange’s declared architecture and controls.

  3. 03

    Data & privacy

    Platform data is processed and stored in the European Union on Microsoft Azure, with one documented exception for live-voice discovery. Individuals can obtain their data and record rights requests, and erasure runs through a governed, verified procedure. The subprocessors the platform relies on are stated.

  4. 04

    AI governance

    The platform’s assistants analyse and recommend; they do not decide. Consequential actions — publishing a capability, selecting a proposal, contacting an external party — are authorized by a person. A search result, a fit assessment and a buyer’s approval are distinct records. Model access is governed through the platform’s own identity; application code holds no provider keys.

  5. 05

    Capability & software assurance

    Publication is governed: a capability version reaches the marketplace only through a release gate the server enforces. Uploaded material is analysed in an isolated environment for known vulnerabilities, exposed secrets and insecure configuration before any assistant or reader may use it, and unresolved findings block publication. Evidence about a capability is recorded and shown with that capability, separately from this statement about the platform.

  6. 06

    Assurance status

    No independent certification, audit or penetration test is claimed today. The statements on this page rest on the platform’s own checks against the deployed service, observed behaviour and AI Exchange’s declarations, each marked with how it is known. A controlled, more detailed assurance record is supplied on request after a person has reviewed the request; nothing unlocks by signing in.

Security & architecture assurance

AI Exchange completed a self-assessment of the deployed Azure workload against the five pillars of the Microsoft Azure Well-Architected Framework on 2026-09-18.

The review found established controls in areas including identity-based access, private service boundaries, encryption at rest and in transit, infrastructure as code and controlled releases. It also identified material improvement priorities, particularly around service resilience and redundancy, recovery objectives and testing, and performance targets and capacity engineering.

Azure Advisor provides an additional ongoing configuration and operational signal for the deployed subscription.

This is an AI Exchange self-assessment, not a Microsoft review, certification or independent audit. Detailed scored results and remediation evidence are available through the deeper-assurance process.

  1. Azure workload architecture

    Well-Architected self-assessment across five pillars, 2026-09-18.

    Completed
  2. AI risk governance

    Assessment against the NIST AI Risk Management Framework not yet performed.

    Pending
  3. Cloud control posture

    Assessment against the CSA Cloud Controls Matrix not yet performed.

    Pending

Current assurance status

  • Self-assessed and evidence-backed: every statement says how it is known.
  • No independent certification, audit or penetration test is claimed.
  • Deeper assurance is available on request, reviewed by a person.

The questions

  1. 01Who operates AI Exchange, and what does it take responsibility for?
  2. 02Where is data processed and stored, and does anything leave the EU?
  3. 03Which third parties process data on AI Exchange’s behalf?
  4. 04How is access controlled, and how are organizations kept apart?
  5. 05How is the service itself secured?
  6. 06What happens to material my organization uploads?
  7. 07Which AI models and providers are used, and how are they reached?
  8. 08What does the AI do, what can it decide on its own, and what always requires a person?
  9. 09What rights do individuals have over their data, and how long is it kept?
  10. 10Which certifications or independent attestations exist?
  11. 11How do I report a vulnerability, and how are incidents handled?
  12. 12What availability and release posture is claimed?

01

Who operates AI Exchange, and what does it take responsibility for?

Declared by AI ExchangePublished documentNot claimed

AI Exchange operates the platform that connects business demand, reusable AI capability, evidence and governed interaction between participants. It is responsible for the security and operation of the AI Exchange platform, including its identity and authorization boundaries, governed workflows, evidence and publication controls, and actions performed by the platform. Responsibilities outside that platform boundary remain with the relevant participants unless AI Exchange explicitly assumes them under the applicable service or transaction terms. The operating legal entity, registration details and formal data-protection role remain subject to the published legal documentation and are identified there where still pending.

How this is known · 4 statements
  1. Declared by AI Exchange

    AI Exchange is responsible for the security and operation of the AI Exchange platform; responsibilities outside that platform boundary remain with the relevant participants unless AI Exchange explicitly assumes them under the applicable service or transaction terms.

    As of 2026-09-15

  2. Published document

    Terms, Privacy, Cookies and Legal Notice are governed, versioned documents. English governs; no translation is approved. Each document states what is still pending before production.

    As of 2026-09-15

  3. Not claimed

    Not claimed: The operating legal entity, its registration and its address.

    Listed as pending before production in the Legal Notice.

  4. Not claimed

    Not claimed: The platform’s controller or processor role under GDPR, a data-protection contact, and contractual data-residency commitments.

    Not yet decided. The processing locations above are the configured facts, not a commitment.

Pending before production, as the legal documents themselves state it
  • TermsLegal review of the full text before any production acceptance is recorded
  • TermsBinding the stored acknowledgement to this version identifier
  • PrivacyLegal review against GDPR Art. 13/14 disclosure requirements
  • PrivacyBinding the stored acknowledgement to this version identifier
  • Legal noticeLegal operator name and registered address
  • Legal noticeCompany/tax registration details

02

Where is data processed and stored, and does anything leave the EU?

Declared by AI Exchange

Platform data is processed and stored in the European Union on Microsoft Azure: the application and its data in Azure Spain Central, the AI models in Azure Sweden Central. One exception is declared: the live voice discovery path is configured to allow processing outside the EU data zone, so EU-only processing is not guaranteed for that path. Database backups are kept in the same region for 7 days, without a geo-redundant copy.

How this is known · 3 statements
  1. Declared by AI Exchange

    The application and its data are deployed in Azure Spain Central; the AI models (Azure AI Foundry) in Azure Sweden Central. Both are EU regions.

    As of 2026-09-15

  2. Declared by AI Exchange

    Document understanding is bound to the EU data zone of the model resource. Live voice discovery is configured to allow global processing; EU-only processing is therefore not guaranteed for that path.

    Where EU-only processing is required, live voice should not be used.

    As of 2026-09-15

  3. Declared by AI Exchange

    Database backups are retained for 7 days in the same region. Geo-redundant backup is off.

    As of 2026-09-15

03

Which third parties process data on AI Exchange’s behalf?

Declared by AI Exchange

Two: Microsoft Azure (hosting, database, storage and AI models) and Hostinger (transactional email such as verification and password reset). This is the set named by the platform’s own configuration. A reviewed subprocessor list with processing agreements is not yet published.

How this is known · 1 statement
  1. Declared by AI Exchange

    Hosting, database, storage and models: Microsoft Azure. Transactional email: Hostinger. No other processor is declared.

    This is the set the configuration names, not a reviewed subprocessor list.

    As of 2026-09-15

04

How is access controlled, and how are organizations kept apart?

Observed on the live platformNot claimed

Accounts sign in with a verified email address and a password, and sessions are controlled by the server. Each organization is an isolated authorization domain: a private organization’s profile is withheld from other signed-in users, not only from anonymous visitors, and a session never confers authority over another organization. Password-reset requests reveal nothing about whether an address is registered. Single sign-on and multi-factor authentication are not offered today.

How this is known · 4 statements
  1. Observed on the live platform

    An account must verify its email address before it can sign in. Sign-in is refused until the address is verified.

    As of 2026-09-15

  2. Observed on the live platform

    A password-reset request for an unknown address is answered exactly like one for a known address, so the form cannot be used to discover accounts.

    As of 2026-09-15

  3. Observed on the live platform

    Organizations are separate tenants. A private organization’s profile is withheld from other signed-in users, not only from anonymous visitors: a session is not authorization over another organization.

    As of 2026-09-14

  4. Not claimed

    Not claimed: Single sign-on or federated sign-in for customer accounts, and multi-factor authentication.

    Customer sign-in is email and password with mandatory verification. No customer SSO or MFA is offered today.

05

How is the service itself secured?

Checked against the deployed platformDeclared by AI Exchange

The public boundary is served over HTTPS only. Core data and model services are not directly exposed to the public Internet. Workloads authenticate to platform infrastructure by identity rather than stored credentials, and storage and service access is identity-based. The infrastructure is defined as code, released through a controlled process, and its deployed posture is checked against AI Exchange’s declared architecture and controls.

How this is known · 3 statements
  1. Checked against the deployed platform

    HTTPS is enforced on the public surface.

    As of 2026-09-15

  2. Checked against the deployed platform

    Workloads authenticate to platform infrastructure by identity rather than stored credentials; secrets are held in a key store and referenced, never copied into configuration.

    As of 2026-09-15

  3. Declared by AI Exchange

    Infrastructure is defined as code, released through a controlled process, and its deployed posture is checked against AI Exchange’s declared architecture and controls.

    This is the platform checking itself. It is not an independent audit.

    As of 2026-09-15

06

What happens to material my organization uploads?

Declared by AI ExchangeObserved on the live platform

Uploaded material is held in the platform’s EU storage and is not published unless the organization publishes a capability that uses it. Uploaded files and connected repository snapshots are analysed in an isolated environment for known vulnerabilities, exposed secrets and insecure configuration before any assistant or reader may use them; material that fails that analysis is never used. A capability version with unresolved findings cannot be published, and the refusal is enforced by the server. Antivirus-style malware scanning is not performed today.

How this is known · 3 statements
  1. Declared by AI Exchange

    Artifacts uploaded for a capability are assessed for known vulnerabilities in their components before publication, and the assessment is bound to the exact material assessed.

    As of 2026-09-15

  2. Observed on the live platform

    A capability version whose uploaded artifacts carry unresolved security findings cannot be published. The refusal is made by the server and cannot be overridden from the publishing form.

    As of 2026-09-13

  3. Declared by AI Exchange

    Uploaded files are analysed in an isolated environment for known vulnerabilities, exposed secrets and insecure configuration before any assistant or reader may use them; material that fails that analysis is never used. Antivirus-style malware scanning is not performed today.

    As of 2026-09-18

07

Which AI models and providers are used, and how are they reached?

Declared by AI Exchange

AI features run on model deployments that AI Exchange operates on Microsoft Azure AI Foundry, reached through a provider-neutral gateway. Model access is governed through the platform’s own identity; application code holds no provider keys, and no other model provider is used today. Prompts and documents are processed by those deployments in the EU, with the live-voice exception described under data location.

How this is known · 1 statement
  1. Declared by AI Exchange

    Model access is governed through a provider-neutral gateway to deployments AI Exchange operates on Azure AI Foundry, under the platform’s own identity; application code holds no provider keys, and no other model provider is used today.

    As of 2026-09-15

08

What does the AI do, what can it decide on its own, and what always requires a person?

Declared by AI ExchangeObserved on the live platformNot claimed

AI Exchange’s assistants help an organization describe a business need, help a builder describe a capability, and assess how well a capability fits a stated need. They produce assistance and recommendations, never binding decisions: a search result, a fit assessment and a buyer’s approval are distinct records, and fit is assessed against the organization’s own declared context. Publishing a capability version, selecting a proposal and contacting an external party on the platform’s behalf require a human decision; no automated component performs them. AI Exchange does not claim a formal model-evaluation programme today.

How this is known · 5 statements
  1. Declared by AI Exchange

    AI Exchange’s assistants help an organization describe a business need, help a builder describe a capability, and assess how well a capability fits a stated need. They produce assistance and recommendations, never binding decisions.

    AI Exchange does not claim a formal model-evaluation programme today.

    As of 2026-09-17

  2. Observed on the live platform

    Discovery does not produce a verdict. A search result, a fit assessment and a buyer approval are distinct records, and fit is assessed against the organization’s own declared context and constraints.

    As of 2026-09-15

  3. Declared by AI Exchange

    Consequential actions require a human decision: publishing a capability version, selecting a proposal, and contacting an external party on the platform’s behalf. No automated component performs them.

    As of 2026-09-15

  4. Not claimed

    Not claimed: The platform’s role under the EU AI Act, its transparency position for AI-generated output, and model evaluation results.

  5. Not claimed

    Not claimed: No assessment of the platform against the NIST AI Risk Management Framework has been performed yet.

    The framework is held as a designated reference source; the assessment itself is pending.

09

What rights do individuals have over their data, and how long is it kept?

Declared by AI ExchangeNot claimed

A signed-in person can download their personal data (access and portability) and record access, portability, erasure and rectification requests from their account page; each request carries a one-month deadline, and erasure is carried out by an authorised operator through a governed procedure whose result is verified before the request is closed. A person who cannot sign in uses the contact form. Retention periods have not yet been decided: data is kept while the account exists, nothing is expired automatically, and backups keep a copy for 7 days after erasure.

How this is known · 2 statements
  1. Declared by AI Exchange

    A signed-in person can download their personal data (access and portability) and record access, portability, erasure and rectification requests from their account page, each with a one-month deadline. Erasure is carried out by an authorised operator through a governed procedure whose result is verified before the request is closed.

    A person who cannot sign in goes through the contact form. Backups keep a copy for 7 days after erasure.

    As of 2026-09-17

  2. Not claimed

    Not claimed: Retention periods for account data, discovery conversations and uploaded material.

    Not yet decided. Data is kept while the account exists and nothing is expired automatically until a period is decided.

10

Which certifications or independent attestations exist?

Declared by AI ExchangeNot claimed

None today. AI Exchange does not claim SOC 2, ISO 27001 or any other certification, and claims no independent audit, penetration test or attestation. The statements on this page are self-assessed and evidence-backed, each marked with how it is known.

How this is known · 2 statements
  1. Declared by AI Exchange

    No certification — SOC 2, ISO 27001 or any other — is claimed, and no independent audit or attestation is claimed.

    As of 2026-09-15

  2. Not claimed

    Not claimed: No assessment of the platform against the CSA Cloud Controls Matrix has been performed yet.

11

How do I report a vulnerability, and how are incidents handled?

Not claimed

Security concerns can be submitted through the contact form, and are handled by the platform’s operators. A dedicated security contact, a published disclosure policy and a published incident-response process do not exist yet.

How this is known · 1 statement
  1. Not claimed

    Not claimed: A dedicated security contact, a published vulnerability-disclosure policy, an incident-response process and penetration-test results.

    To report a security concern today, use the contact form.

12

What availability and release posture is claimed?

Declared by AI ExchangeNot claimedObserved on the live platform

Releases follow a controlled process: a release is prepared and verified by automation, and publishing it to a production environment is a decision reserved to a person. AI Exchange currently operates a single pre-launch environment; a separate production environment does not exist yet. No availability target, maintenance window or status page is published. A self-assessment of the deployed workload against the Azure Well-Architected Framework was completed on 2026-09-18; its scored results are supplied under deeper assurance.

How this is known · 5 statements
  1. Declared by AI Exchange

    AI Exchange currently operates a single pre-launch environment. No separate production environment exists yet.

    As of 2026-09-15

  2. Declared by AI Exchange

    Releases follow a controlled process: automation prepares and verifies a release; publishing it to a production environment is a decision reserved to a person.

    As of 2026-09-15

  3. Not claimed

    Not claimed: Availability targets, maintenance windows and status reporting.

  4. Declared by AI Exchange

    A self-assessment of the deployed workload against the five pillars of the Azure Well-Architected Framework was completed on 2026-09-18. It found established controls and material improvement priorities; the scored results are supplied under deeper assurance.

    A self-assessment by AI Exchange, not a review by Microsoft or an independent party.

    As of 2026-09-18

  5. Observed on the live platform

    Azure Advisor provides an additional ongoing configuration and operational signal for the deployed subscription; its recommendations are tracked together with the review findings.

    As of 2026-09-18

How to read this page

Six ways a statement can be known. None of them is a badge.

  • Checked against the deployed platform

    Confirmed by AI Exchange’s own automated checks against the deployed platform on the date shown. Not a certification.

    2 statements

  • Observed on the live platform

    A behaviour observed on the deployed platform on the date shown.

    6 statements

  • Declared by AI Exchange

    Stated by AI Exchange from its platform configuration, code or accepted design. Nothing outside the platform checked it.

    16 statements

  • Published document

    A versioned, human-approved document the platform publishes.

    1 statement

  • Independently certified

    Attested by an independent third party. None today.

    0 statements

  • Not claimed

    AI Exchange does not claim it. The answer says whether it is not offered, not decided, or pending.

    9 statements

These are not the evidence classes used for capabilities — those are on each capability page and explained under principle 04. The vocabulary is different on purpose, so that "verified" means one thing on this site. The register behind this page is maintained by hand and re-read against its sources on the date shown.

Deeper assurance

Need more than this page? Ask for it.

A more detailed assurance record exists — the full statements behind each answer, their dates and boundaries, and a summary of the automated control sweep. It is supplied deliberately, to a named reviewer, after a person at AI Exchange has reviewed the request.

Signing in does not unlock it: a registered account is not a confidentiality agreement. A request is reviewed by a person and answered outside the product.

Ask a question

Request deeper assurance

Tell us who is asking and why. A person at AI Exchange reviews every request; approved material is delivered outside the product, to you.

Rate-limited and honeypot-protected; the request is recorded, and reviewed by a person.

Capability evidence lives elsewhere

Evidence about a capability is on that capability's page.

Each published capability shows what has been established about it by class — declared, verified, expert-reviewed, attested, observed, buyer-reported — with absence stated. A signed-in reader sees every record; an anonymous visitor sees the summary. Nothing on this page speaks for a capability.

Browse capabilities Create an account