Spentia compliance portal
ARIA security and compliance overview.
Sovereign, EU-only, audit-ready. This page gives DPOs and procurement teams the current operational facts behind ARIA.
Hosting and data residency
Production data flows are EU-centered by design.
No customer personal data is processed outside the European Union. TLS certificates are issued by Let's Encrypt; no ARIA customer personal data is exchanged with the certificate authority.
| Asset | Provider | Location |
|---|
Subprocessors
Active subprocessors used by ARIA.
Security measures
Public summary of Article 32 controls.
This public view exposes categories and labels only. Internal configuration details remain restricted.
Compliance
Built for European B2B procurement.
GDPR
Spentia acts as Processor under Article 28 on behalf of the Customer as Controller.
EU AI Act
ARIA is not classified as a high-risk AI system under Annex III. Participant transparency is handled during onboarding.
AI transparency noticeItalian deployments
ARIA is aligned with Law No. 132/2025 worker information duties and the defensibility requirements of the Statuto dei Lavoratori.
Italian compliance memorandumCertifications and audits
External assurance roadmap.
We currently rely on technical audits and operational controls documented in our Article 30 records. External certifications are part of our 2026-2027 roadmap.
Operational status
Production health is monitored continuously.
Dedicated public status page coming soon. Health endpoint is available.
Data subject rights
Participants keep GDPR rights through their employer DPO.
If you participated in an ARIA campaign, exercise GDPR rights by contacting your employer's DPO. For technical routing questions, write to dpo@spentia.com.
Contact