Sources & method
Transparency on what feeds the assistant and the editorial corpus, and how we verify what it tells you.
How answers are built
The assistant does not answer from general knowledge: every question is matched by semantic similarity (embeddings) against a base of indexed passages, and the model is instructed to answer only from the retrieved passages, citing them as [Source N]. If nothing relevant is found, it says so instead of guessing.
The knowledge base is built from three streams: original editorial content (guides, glossaries, checklists) written and reviewed by us; an automated nightly crawl limited to the whitelisted official sources below; and editorial spin-offs (e.g. the CyberWatch digest) that go through the same editorial review before being published.
Whitelisted official sources
Only these domains are crawled automatically, and only under an open licence or as public-domain institutional content — never behind a paywall or a restrictive licence.
Cyber security
- cert-agid.gov.it
- agid.gov.it
- enisa.europa.eu
- cisa.gov
- nist.gov
- attack.mitre.org
- owasp.org
Physical security
- protezionecivile.gov.it
Travel security
- gov.uk
- smartraveller.gov.au
Information security
- garanteprivacy.it
- edpb.europa.eu
- eur-lex.europa.eu
- gazzettaufficiale.it
- europarl.europa.eu
Attribution & licences
Some sources require a specific attribution notice, shown next to the cited passage in chat and in the audit log:
- cert-agid.gov.it — Fonte: CERT-AGID — contenuto rielaborato, originale in licenza CC BY 4.0
- enisa.europa.eu — © European Union Agency for Cybersecurity (ENISA) — contenuto rielaborato
- attack.mitre.org — © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
- owasp.org — © OWASP Foundation — originale in licenza CC BY-SA 4.0 (creativecommons.org/licenses/by-sa/4.0/); contenuto qui rielaborato in forma di sintesi.
- protezionecivile.gov.it — Fonte: Dipartimento della Protezione Civile-Presidenza del Consiglio dei Ministri
- gov.uk — Contains public sector information licensed under the Open Government Licence v3.0
- smartraveller.gov.au — © Commonwealth of Australia — Smartraveller, originale in licenza CC BY 4.0; contenuto rielaborato
- edpb.europa.eu — © European Data Protection Board — contenuto rielaborato
- eur-lex.europa.eu — © Unione europea, 1998-2026 — fonte: EUR-Lex (eur-lex.europa.eu); contenuto rielaborato
- europarl.europa.eu — © European Union – Source: European Parliament
What we deliberately leave out
Sources cited but never crawled. Some authoritative sources are never crawled automatically: we only use them as references in our editorial content, respecting each one’s conditions. Today they are:
- acn.gov.it and csirt.gov.it — their legal notices require written authorisation to reproduce content; we have requested it and, until it is granted, these sites remain references only.
- poliziadistato.it — content under a CC BY-NC-ND licence (non-commercial, no derivatives), incompatible with reuse in this service.
- viaggiaresicuri.it — no open licence declared and a “deep linking” ban in the site’s conditions: we cite it as a reference pointing to the homepage only, with no direct links to internal pages.
- travel.state.gov — suspended since 6 August 2026: the site protects its pages with an anti-bot challenge, which we do not circumvent as a matter of policy. It will return to the whitelist only through ordinary access, an official API/feed or an authorisation.
This list only changes with a documented decision: if a source enters or leaves the whitelist, this page is updated.
Every crawl request respects the target site’s robots.txt (crawl-delay included) and a static safety list of disallowed paths, even when robots.txt itself cannot be fetched.
The limits of this method
Source grounding reduces errors, it does not eliminate them: the model can misunderstand a passage, combine sources incorrectly or translate imprecisely. The assistant only knows what has been indexed: the absence of an answer does not mean the information does not exist. That is why answers always cite their sources — the correct way to use them is to verify them — and answer quality is periodically checked on samples with human review. How the system works, what it records and what responsibilities remain with its users is described in the AI notice.
Reports & corrections
If you believe that Portal content improperly reproduces material you hold rights to, contains an error or a missing attribution, or concerns you inaccurately, write to compliance@securityportal.it. To help us act quickly, include: who you are and how to reach you, the address (URL) of the content, what you contest and — for rights violations — on what basis. We confirm receipt within 5 working days and give a reasoned reply normally within 10 working days; in clear-cut cases the content is suspended immediately, pending assessment. For requests about personal data, the privacy notice applies.
General questions about a source or the method: info@securityportal.it