Bolt.new (StackBlitz)
high riskAI Coding Assistantbolt.new, stackblitz.comverified 2026-06-27profile 25% complete
Data-handling profile
- Trains on input
- Unknown / not publicly stated
- Retention
- StackBlitz states AI Inputs/Outputs may be used to operate, maintain, and improve services on an aggregated/anonymized/de-identified basis; opt-out availability is described as depending on account type/plan but specific tier mechanics and retention periods are not clearly published. Third-party AI providers are contractually bound to confidentiality.
- Data region
- unknown
- Certifications
- none listed
- DPA available
- No
- Breach history
- none known
- EU AI Act
- AI coding assistant; StackBlitz's public documentation lacks clarity on training-data use mechanisms, retention, and breach procedures, which is itself a governance/transparency gap worth flagging.
Sources
- https://stackblitz.com/privacy-policy
- https://support.bolt.new/account-and-subscription/corporate-commercial
- https://verifywise.ai/ai-trust-index/bolt-newlink no longer resolves
Every fact above is drawn from the vendor's public documentation, reviewed by a human, and version-stamped. Monitored daily for changes. 1 of these 3 links no longer resolve. We record what we relied on rather than deleting it, so the trail stays auditable — but a struck-through source cannot be re-checked today.
Control mapping
Obligations this vendor triggers, each attributable to the fact it rests on — for your supplier register, not a compliance determination.
- EU AI Act Art. 50 — Transparency obligations for AI systemsunknown
Vendor does not publicly state whether it trains on inputs. Unresolved: treat as a question for the vendor, not as a pass.
- EU AI Act Art. 26 — Obligations of deployers of high-risk AI systemsapplies
Applies to your organisation as deployer, independent of vendor. Assign human oversight, keep logs, and monitor operation where this tool is used in a high-risk context (Annex III duties apply from 2 Dec 2027).
- ISO/IEC 27001 A.5.19 — Information security in supplier relationshipsapplies
Bolt.new (StackBlitz) processes organisational data as a supplier. Include this vendor in the supplier register and risk assessment.
- ISO/IEC 27001 A.5.20 — Addressing information security within supplier agreementsgap
dpa_available = false. No DPA identified — security and processing terms are not contractually established.
- ISO/IEC 27001 A.5.23 — Information security for use of cloud servicesapplies
Cloud AI service; trains_on_input = unknown. Define acceptable-use and configuration rules for this cloud service.
- ISO/IEC 42001 A.10.3 — Suppliers of AI systems and servicesapplies
No certifications listed. No AI-management certification identified; assurance must come from your own supplier assessment.
- GDPR Art. 44–49 — International transfers of personal dataunknown
Vendor does not publicly state its processing region. Residency unresolved — required before transferring personal data.
- NIS2 Art. 21(2)(d) — Supply chain securityapplies
AI vendor forms part of your ICT supply chain. In scope for entities covered by NIS2; include in supply-chain risk measures.
- DORA Art. 28 — General principles for ICT third-party riskapplies
AI vendor is an ICT third-party service provider. For financial entities: register of information and contractual requirements apply.
Change history
No material changes recorded since monitoring began.