Crawler statement

Operator

PassportAI is a regulatory research service by itsaura for compliance departments of financial institutions in the EU, the EEA and the United Kingdom. It answers questions about EU law and the national rules of home and host states, with every statement linked to its public source. The crawler collects those sources.

Public legal and supervisory material only

It does not collect personal profiles, does not log in, does not submit forms and does not fetch anything behind a login or paywall. The automated crawler does not pass CAPTCHAs (see the supervised session below for the one exception). Content is used to answer research questions with citations to the original source.

Rules the crawler follows

Supervised browser session (separate from the crawler). A small number of public regulator sources that sit behind a CAPTCHA or browser check are fetched at most once a month in a visible desktop browser, operated and watched by a person at itsaura, from a different (office) connection. Where an access check appears, that person completes it by hand; nothing solves CAPTCHAs automatically and no check is bypassed. In that session the browser identifies as an ordinary desktop browser, not as PassportAI-research, and its requests are not signed. It follows the same rules otherwise: robots.txt per path, a slow human pace (at least six seconds between pages on a host), and only public documents. Sites that would rather not be visited this way can tell us through the Support button at the top of this page, and we will stop.

Disclosed exceptions

On the explicit decision of itsaura, and only for these paths, the crawler fetches material that the site's robots.txt closes for general crawlers. Each is official public material, fetched slowly, and each publisher has been or is being informed; we stop on request. The material is used for reference only: PassportAI cites and links to the original source and does not republish it as a dataset, and the site owners have been notified.

User agent, IP addresses, signatures

User-agent
Mozilla/5.0 (compatible; PassportAI-research; +https://passportai.eu/bot)
Robots.txt token
PassportAI-research
Source IP addresses
62.83.19.68
2a0a:4cc0:61:4f1d:583c:eff:fecf:2041
Web Bot Auth key directory (HTTP Message Signatures, RFC 9421)
https://passportai.eu/.well-known/http-message-signatures-directory
Signature-Agent
"https://passportai.eu"

Requests carry Signature-Agent, Signature-Input and Signature headers (Ed25519, tag web-bot-auth, covering @authority and signature-agent). A request that claims to be PassportAI-research but comes from another address and carries no valid signature is not ours.

Blocking or slowing the crawler

Add this to your robots.txt to block the crawler completely:

User-agent: PassportAI-research
Disallow: /

Or ask for a slower pace:

User-agent: PassportAI-research
Crawl-delay: 10

Changes are picked up on the next run. You can also contact us through the Support button at the top of this page and we will exclude your site or paths by hand.

Questions, problems, abuse

Use the Support button at the top of this page (category "Other") and mention the host name and, if possible, a timestamp from your logs. We answer on working days and stop crawling a site immediately on request.