Certification

ISO27001

ISO27001 is the international standard for Information Security Management Systems. Independent auditors assess whether an organisation's processes for handling sensitive data, managing security risk, and responding to incidents meet the standard.

Our certified information security commitments
  • Absolute data sovereignty

    Customer data does not leave the European Economic Area. If it does, it complies with GDPR through Standard Contractual Clauses.
  • No uncontrolled environments

    Customer data is never sent to or processed in an environment outside our direct control or that of our contractually-bound AI provider.
  • Encryption standards

    Encryption at rest at the disk level. Encryption in transit via HTTPS with TLS, routed to provider data centres within the EU.
  • Strict purpose limitation

    Strict purpose limitation. Customer data is used only for service delivery, billing, and auditing. Data minimisation. Customer rights of access, correction and deletion
  • Data Processing Agreements

    Data Processing Agreements with each AI service provider.
Data handling

How we handle AI-specific data

No training

No training on your data. Customer prompts and responses are not used to train models.

Auditing only

Auditing only. Stored prompts and responses kept strictly for auditing.

Optional caching

Provider-side caching is possible for up to 24 hours within the secure EU environment. Disabled on request.

Where

Where customer data goes

Customer data is confined to two secure environments, both in the European Union: our internal systems (EU-based, ISO 27001-certified platform), and the AI service provider (or self-hosted models for sovereign deployments).

For provider-hosted models, customer prompts are sent for real-time processing to the provider's EU-based servers. The provider does not store the data or use it for training, contractually guaranteed under our DPA.

Get in touch