For data protection officers

Does the privacy notice reflect what's technically actually running?

Data protection officers document AI-related processing in the privacy notice, in the record of processing activities under Art. 30, and in the DPIA — but the technical reality on the domain often diverges from the documented statement. CERTavia checks exactly this gap: whether AI governance declarations are technically actually live and consistent.

The gap between document and reality

Paper is not infrastructure

The privacy notice describes how AI crawlers, training data opt-out, and automated decisions are handled. Whether that description matches the actual technical configuration — robots.txt directives, AI policy URL, deepfake disclaimer, contact point for AI inquiries — is hard to verify without a technical check. This gap is a risk both for GDPR documentation obligations and for the overlap with Art. 50 of the EU AI Act.

CERTavia checks the technical infrastructure layer independently of the documentation and delivers a deterministic, cryptographically signed comparison: is what's stated in the privacy notice technically actually implemented?

The relevant validation cluster

AI Governance Hard Gate in detail

For data protection officers, this cluster is the immediately relevant check area.

ai.txt and AI policy URL

Checks whether a machine-readable AI policy is actually reachable at the expected address and whether its content is consistent with the AI use described in the privacy notice.

Privacy AI section

Checks whether the privacy notice contains an AI-specific section and whether it matches the technical robots.txt and crawler configuration.

AI training opt-out status

Checks whether declared opt-out signals for AI training data are technically consistently implemented via robots.txt, meta tags, and HTTP headers — not merely claimed in a document.

Deepfake disclaimer and contact point

Checks the presence and technical reachability of a deepfake disclaimer and a dedicated contact point for data subjects' AI-related inquiries.

Note on the parameter base: This cluster is the layer at which the regulatory requirements from Art. 50 of the EU AI Act become technically verifiable — complementing the GDPR documentation obligations data protection officers already maintain.

Record of processing and DPIA

A technical proof for the documentation

For the record of processing activities under Art. 30 GDPR and for data protection impact assessments (DPIA) of AI-supported processing, a technical proof showing that the declared safeguards are actually active is helpful. The CERTavia report delivers this proof as a cryptographically signed, timestamped document — not a substitute for the legal DPIA assessment, but a technical building block within it.

The overlap between GDPR requirements and the EU AI Act particularly concerns automated decision-making and the transparency obligations under Art. 50. More on the EU AI Act overview page.

Collaboration with IT

A shared finding instead of separate perceptions

The CERTavia report gives data protection officers and IT leaders the same deterministic finding — a shared basis for identifying and closing discrepancies between documented and actual configuration, instead of managing them in separate review processes.

CERTavia itself GDPR-compliant

Can I use CERTavia as a data processor?

Yes. The first question any data protection officer asks when adopting a new tool is: what about the provider's own data protection compliance? Here are the answers:

DPA available

A data processing agreement under Art. 28 GDPR with a full sub-processor list (Hetzner, Cloudflare, Stripe, Resend) and TOMs is available and is deemed agreed upon contract conclusion. Countersigned within 2 business days on request.

Get the DPA →

Scan = public data

CERTavia scans exclusively publicly accessible technical infrastructure parameters (DNS, HTTP headers, public web content). Page content, your visitors' user data, and internal system data are not collected.

§ 19 Privacy notice →

Hosting in the EU

The scan API and database run at Hetzner in Germany. The website runs on Cloudflare Pages (EU-US DPF). Payments via Stripe (EU-US DPF). Email via Resend (SCCs). All sub-processor details in the DPA.

Sub-processor list →
Starting at EUR 490

Pricing for data protection officers

Basic EUR 490

PDF audit report, cryptographic signature, Sovereign Vault available for 90 days (local archiving required afterward). Suitable for the initial comparison check between privacy notice and technical reality.

Pro EUR 1,490

Sovereign Vault with no automatic expiration date, machine-readable verification URL, JSON output. Suitable as technical proof for Art. 30 documentation and DPIA.

The report is delivered directly by email; customer portal access is available on request (automatically included with Annual and Enterprise plans).

For external data protection officers

Managing multiple clients?

As an external DPO, you typically scan not one domain but a portfolio. CERTavia is suitable for use across multiple clients: you receive an independent, cryptographically signed result per scan — directly forwardable to the respective contact at the company.

For portfolio-based use and volume terms: request via the contact form, noting the number of clients.

Check now

Comparison in 90 seconds

The quick scan delivers your domain's Layer 0 result in 90 to 120 seconds. Free, with immediately available JSON output in the Full Scan.