Skip to content

Four rules apply to every company in the group, in any sector. They are followed by what we rule out and by a summary of the regulatory framework in which we operate.

Entry
Principles: AI reads, people decide
Part
I · The group
Revised
Reading
3 min
  1. AI reads.
    People decide.

    In every sector in which we operate, artificial intelligence reads, compares and flags. None of its output becomes a decision without verification by a professional of that sector, who takes responsibility for it.

    In practice

    In the first sector, ComproCausa’s pre-evaluations are checked by its team and validated on the merits by an appointed lawyer. Italian law establishes the same principle for the intellectual professions: artificial intelligence plays a supporting role and the decision rests with the professional.1

  2. Every reference checked,
    every figure with its source.

    An analysis is only as reliable as the sources on which it rests. References are checked against the original source; statistics are published with their source and reference year, or not at all. When a figure derives from our own calculation on public data, we state so explicitly.

    In practice

    Kesita checks every citation against the registry. On this site every statistic carries a source and a year, and links to the Sources page.

  3. Data in Europe.

    Whatever the sector, the platform on which the group’s companies operate is hosted in the European Union, on Microsoft Azure, in the West Europe region.

    In practice

    Databases are not exposed to the internet, keys and access credentials are held in a dedicated encrypted vault, and staff reach the infrastructure only through a private network.

  4. Separate companies,
    shared standards.

    Each company in the group has its own sector, its own data, its own infrastructure and its own accounts. Security rules and operating procedures are common to all of them.

    In practice

    Each company is isolated on four planes: resources, identity, secrets and network. The method and the platform are shared; each company’s data remains its own.

What we
rule out

This short list carries the same weight as the principles. We keep it prominent because it is the part most easily overlooked.

  • We do not publish figures we are unable to document.

    CheckThe sources

  • We do not promise outcomes; the timeframes we give are indicative.

  • We do not claim certifications we do not hold.

    CheckThe framework

  • We do not entrust artificial intelligence with decisions that belong to people.

  • We do not attribute to the group’s companies activities they do not carry out.

    CheckThe companies

  • We do not present a new sector before we have concrete results.

  • We do not use AI-generated people to portray real events.

The regulatory framework, in brief

The rules relevant to our work, in every sector, set out in accessible terms. This summary does not constitute legal advice; it describes how we apply them.

Regulation (EU) 2024/1689aAI Act · roles
The European regulation distinguishes between those who develop an artificial intelligence system (the provider) and those who use it (the deployer). A company of the group that develops and uses its own system holds both roles and is accountable both for its design and for its use. This is currently the case for ComproCausa.
Law 132/2025 · art. 13Human validation
Italy’s AI law provides that, in the intellectual professions, artificial intelligence may perform only supporting activities: the intellectual work and the decision remain with the professional, and the client must be informed. We apply this principle in every sector; in the first, no ComproCausa pre-evaluation is sent to the applicant without a lawyer’s validation.1
Regulation (EU) 2016/679bGDPR · personal data
We collect only the data we need and state the purpose for which we collect it. This site uses no profiling cookies and no analytics; the contact form requests only the information needed to respond. Details are set out in the privacy notice.
HostingData location
Data is kept in the European Union: the platform of the group’s companies is hosted on Microsoft Azure, in the West Europe region. Each company has its own infrastructure, separate from that of the others.
SectorsSector regulation
Every sector is governed by its own rules and authorities. The company we establish in it complies with them from the outset, and the professionals who work there are accountable for them.
CertificationsOnly those obtained
At present the group holds no security certification. Any certification obtained in future will be listed in this section, with its reference.
MethodTransparency
Every published statistic refers to a source that can be consulted. The timeframes we communicate are always indicative, and no outcome is guaranteed.

Notes

  1. Note a: Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act).

  2. Note b: Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (General Data Protection Regulation).

Any statement on this site that does not appear to comply with these principles may be reported to us: we will review it and, where necessary, correct it.