New Business Rules in the AI Agentic Age Get the free whitepaper
Trust center

Trust, security & legal

How TapPass protects your data, our security and compliance posture, and every legal document in one place. Built in the EU, for AI you can put into production with confidence.

At TapPass, trust is built into everything we do. From our EU infrastructure to how we handle every action an AI takes, the platform is designed to meet a high bar for security, data protection and compliance. This trust center gives you direct access to the policies, practices and safeguards that protect your data, together with every legal document in one place. We run our own operations on TapPass every day, and extend the same protection to you.

Message from our CEO

"AI that takes action deserves the same accountability we expect from people. We built TapPass so every agent stays under your rules, on the record, and in the EU. Trust is earned through transparency and rigorous practice, and by running our own AI under TapPass, every single day."

Jens Bontinck · Cofounder & CEO, Cogniqor BV

The essentials

Hosting
Hosted in the EU
Data protection
GDPR (Regulation 2016/679)
AI regulation
Built for the EU AI Act
Legal entity
Cogniqor BV
Registered in
Antwerp, Belgium
VAT / KBO
BE 1033.796.306
Service status
Data protection officer
Security contact

Legal documents

The agreements and notices that govern your use of TapPass.

Security & reliability

How we keep the platform safe and available.

How we handle your data

TapPass is built and hosted in the European Union. For the data your agents send through the platform, you are the controller and TapPass acts as a processor on your instructions, under a Data Processing Agreement. For your account and the data you give us directly, such as billing and contact details, TapPass is the controller.

Your data stays yours. We process it to provide and secure the service, and we do not sell it. Where we rely on subprocessors, they are listed on our trust portal and bound by equivalent obligations.

For the full detail, including legal bases, retention periods, international transfers and how to exercise your rights, see the Privacy Policy. Data processing terms for customers are set out in our Data Processing Agreement, available on request via dpo@tappass.ai.

Data processing & privacy — FAQ

Plain answers to the questions security and procurement teams ask most. For the binding detail, see the Privacy Policy and, on request, the Data Processing Agreement.

How does TapPass handle the information our agents send?

TapPass sits between your AI agents and the AI models and tools they use. It checks every request against your organisation's rules before anything happens, and decides in real time whether to allow it, block it, or adjust it. It automatically screens each request for sensitive information such as personal data and secrets. If your rules cannot be loaded, the request is blocked — nothing passes through unchecked.

There are two ways TapPass runs. In one, TapPass only returns the decision and your own systems talk to the AI model, so TapPass never sees the content. In the other, TapPass passes the approved request to the AI model on your behalf — using your own account with that provider — and checks the answer before it is returned.

What information does TapPass process and keep?

While checking a request, TapPass reads the request itself — the text of the prompt, any action the agent wants to take, and which AI model is involved. The screening for sensitive information happens in memory and is not stored as text.

What TapPass keeps afterwards is, first and foremost, a record of the decision: what was allowed or blocked and why, which model was used, the cost, and which agent, user and organisation were involved, with the date and time.

TapPass also keeps a copy of the request and the response so your team can review what your agents did. You control this: it can be switched off so that only the decision record is kept, and no request or response content is stored.

Where is our data stored, for how long, and why?

Your data is stored in a secure database in the European Union — in Belgium — with encrypted backups. TapPass keeps a trustworthy record of every decision so you can always show what your agents did; that record is the heart of the product.

You decide how long records are kept. When a record reaches the end of that period, TapPass deletes it completely — including any stored request and response content, not only the short summary.

Is our data deleted, and can you erase it on request?

Records are kept for as long as they are useful for audit, rather than thrown away after each request — that is what lets you prove what your agents did. They are removed in two ways: automatically, when they reach the end of the retention period you set; and on request, when someone exercises their right to be forgotten.

An erasure request removes that person's information across the platform, including the full text of their requests and responses, while keeping the audit trail verifiable. Backups clear themselves on their normal cycle.

Who can access the information TapPass holds? Who can see what?

Your data is kept strictly separate from every other customer's. This is enforced in two independent ways, so no one outside your organisation can see it.

Inside your organisation, what someone sees depends on their role: everyone can see summaries, and administrators can see the detail. People sign in with your single sign-on or a password.

TapPass staff cannot change your data. In rare support situations, a TapPass administrator can open a view of your workspace that is strictly read-only, limited to your organisation, and lasts at most 30 minutes. Every such view is written to the same tamper-proof record — so we can always show you exactly when your workspace was viewed, and by whom.

What logging and audit information does TapPass keep?

Every decision is written to a tamper-proof record. Each entry is sealed and linked to the one before it and cryptographically signed, so any change or missing entry is immediately detectable.

Everyday system logs contain only technical identifiers — never the content of prompts and never personal data.

You can also send your own audit records to your security monitoring system. This is switched off unless you turn it on, and sensitive fields are removed before anything leaves TapPass.

Does any data leave the EU?

TapPass itself — its servers, its database and its records — runs in the European Union, and your organisation is set to the EU region by default.

The only point where information can leave the EU is the AI model itself, and only if you choose a model hosted outside the EU. That choice is entirely yours: European or self-hosted models keep everything in the EU. When you require it, TapPass enforces EU-only models automatically, and we set this up for European customers.

Two things to be clear about: our built-in assistant uses a US-based model and can be turned off; and every outside company that helps run TapPass is listed, with its location, in the Subprocessors section above.

Subprocessors

The third parties that may process data to help us run TapPass. Each link opens that provider's data-processing terms in a new tab.

ProviderPurposeRegion
Google CloudGoogle Cloud Application hosting and database EU (Belgium)
CloudflareCloudflare DNS Global
ResendResend Transactional email United States
PostHogPostHog Product analytics EU
SentrySentry Error monitoring EU
OpenAIOpenAI Powers the in-product assistant (Jorge) United States
GoogleGoogle (sign-in) Single sign-on, when you enable it Global
Microsoft (sign-in) Single sign-on, when you enable it Global
Additional AI model providers, engaged only when you enable that model with your own key (BYOK). Your prompts are never used to train any model.
AnthropicAnthropic Model inference, on activation United States
Google GeminiGoogle Gemini Model inference, on activation United States
Mistral AIMistral AI Model inference, on activation EU (France)
GroqGroq Model inference, on activation United States
DeepSeekDeepSeek Model inference, on activation China
MoonshotMoonshot (Kimi) Model inference, on activation China
MiniMaxMiniMax Model inference, on activation China
Alibaba QwenAlibaba (Qwen) Model inference, on activation China

We give advance notice before adding a new subprocessor. Tools we use to run our own business (for example code hosting, CRM and monitoring) process our data, not the data you put into TapPass, and are described in our Privacy Policy.

Request documents

Some documents we share on request, usually under a mutual NDA. We respond quickly.

Compliance

The frameworks TapPass is built around.

GDPR EU AI Act EU data residency Belgian Code of Economic Law

A question about trust, privacy or legal?

Whether you need a signed DPA, a security review or a specific document for procurement, we are quick to respond.

Supported by
Start it @KBC
Start it @KBCBelgium's largest startup accelerator
VLAIO
VLAIOFlanders Innovation & Entrepreneurship