Overview
AI Keypass is the canonical AI identity registry. We identify your AI; we do not ingest your AI. The platform stores identity and ownership metadata only — never prompts, outputs, source code, datasets, or secrets. This minimizes the surface area for privacy risk and keeps the trust story simple.
This Trust Center is the single place to find our privacy policy, terms, subprocessors, data residency, uptime commitments, and security architecture. It is maintained alongside the product and updated whenever our infrastructure or practices change.
Company identity & contact
AI Keypass is built and operated by Joe Boroi. We operate as a lean, founder-led company focused entirely on the AI identity problem.
Reach a human. The fastest way to reach us is by email:
info@aikeypass.comFor security disclosures, see the Security section. For sales, the "Contact sales" path on the pricing page routes directly to the founder.
Privacy Policy
What we store. Identity and ownership metadata for registered AI: name, type, purpose, owner, environment, and optional references (repository URL, application URL, internal reference, tags). Identity bindings — declarative mappings that link a registered AI to its identifiers in other systems (e.g. a Vault entity, a SPIFFE ID, a cloud deployment name). Organization membership records, audit events, and hashed API keys.
What we never collect. Prompts, model outputs, training data, source code, datasets, secrets, or behavioral telemetry from the AI systems we register. Identity bindings store only the external identifier — never credentials, tokens, certificates, or secrets from those systems. There is no behavioral data to leak, sell, or train on.
Verification minimizes exposure. A public verification returns only whether the Passport exists, its status, attestation recency, and the organization name. Identifying detail is shown only to members of the owning organization. Private registries reveal only existence and status to non-members.
Retention & your rights. Organization data is retained while the organization is active. An owner can export or permanently delete the organization's data at any time (Settings > Data & privacy); deletion erases the organization and all of its passports, members, keys, and audit records. Any member can export their own personal data or leave an organization at any time. Revoking a Passport preserves its audit trail; a revoked Passport ID is never reassigned. Your login account is platform-managed — to delete it entirely, email info@aikeypass.com. Deleted data may persist briefly in platform backups before permanent removal.
Terms of Service
By using AI Keypass, you agree to the following terms. This summary is provided for transparency; formal legal terms should be reviewed before enterprise procurement.
- Accounts. You are responsible for activity under your account and for keeping API keys secure. Keys are shown once at creation; treat them as credentials.
- Accurate registration. You attest that the metadata you register is accurate to the best of your knowledge. Attestation reconfirms accuracy; it is not a compliance or safety certification.
- No identity spoofing. You may not register AI you do not own or operate, or attempt to forge, guess, or impersonate another organization's Passport IDs.
- Credits & subscription. Each Passport registration consumes one Registry Credit. Every account starts with 5 free credits; additional credit packs are purchased separately and are valid 12 months from purchase (buying a new pack extends the clock on your remaining credits). Gift credits do not expire. Platform access is free for your first year as an early adopter; a paid subscription comes later and is billed separately from credits. Insufficient credits return a 402 error. Linked Identity bindings do not consume Registry Credits.
- Acceptable use. No scraping the registry, no rate-limit evasion, and no use of the service to enable unauthorized surveillance.
- Termination. You may close your account at any time. We may suspend access for violations. Revoked Passport IDs are never reused.
- No warranty. The service is provided "as is." We identify your AI; we do not guarantee the behavior, safety, or compliance of the AI itself.
Subprocessors
AI Keypass relies on the following subprocessors to operate. Each is bound by data processing terms consistent with this policy.
- Cloud hosting & managed database. Application hosting, managed database, and at-rest encryption. Region: US (see Data residency).
- Edge / CDN / WAF. Content delivery, TLS termination, and edge rate limiting for the public verification API.
- Email delivery. Transactional email for invitations and account notifications, limited to registered app users.
- Identity provider. Authentication, session management, and optional SSO.
- Payment processing. Self-serve billing and subscription management. Payment data is handled by the processor — Keypass never stores full card numbers.
We will update this list at least 30 days before adding a new subprocessor that processes customer data.
Data residency
Customer data is stored in a US-based cloud region. The managed database and object storage run in the same region. We do not replicate customer data to regions outside the United States. Enterprise customers with specific residency requirements should contact the founder to discuss dedicated arrangements.
Public verification responses are served from the global edge (CDN), but no customer record data is cached at edge PoPs — only the computed verification response for the duration of its short edge TTL.
Status & uptime
We target 99.9% monthly uptime for the public verification API. For uptime or incident inquiries, contact info@aikeypass.com.
Security & disclosures
See the Security & Trust documentation for the full architecture: encryption in transit and at rest, server-side tenant isolation via row-level security, least-privilege access, hashed API credentials, tamper-resistant audit logging, and input validation.
Responsible disclosure. If you believe you have found a security vulnerability, please report it privately by emailing info@aikeypass.com rather than disclosing it publicly. We acknowledge reports within 2 business days and aim to remediate valid critical issues within 30 days.
Enterprise SSO. Enterprise customers get single sign-on (SAML or OIDC) and SCIM user provisioning configured with your identity provider during onboarding. We work with you one-on-one to wire Keypass into your IdP — it's included, not a paid add-on.
Identity vs. runtime authenticity. AI Keypass verifies registration status and ownership — not runtime cryptographic authenticity. Cryptographic workload binding is on the roadmap (see Roadmap).