Trust Center

What we guarantee, in plain words

Privacy and security are what we sell — so our own infrastructure has to be exemplary. Here is what we actually guarantee, without acronyms. The technical detail is further down, folded away for whoever wants it.

Your guarantees, in 5 points

  1. You sign a contract that binds us

    Before you upload a single document you sign a data processing agreement: it states in writing that the documents are yours, that we only handle them to run the service, that we never hand them to anyone else, and that we delete them when you ask. If we broke it, you would have a contract in your hands — not a promise on a web page.

  2. Nobody reads your documents

    Not our technicians, not an outside supplier. Reading your content in the clear is not part of anyone's job: there is a single emergency procedure, it leaves a trace, and if it were ever used you would be told.

  3. Nothing you write trains an AI

    Not ours and not anyone else's. Your files never reach a public AI service. Each customer has separate encrypted storage, so your content cannot surface in another customer's answers.

  4. You always know where your data is working

    The two lines are different on purpose — pick the one your profession needs.

    Privacy Agent

    • In Europe by default · GDPR and data processing agreement
    • A whole isolated machine, yours alone, for the time you use it
    • Never used for training; separate customer storage prevents cross-customer answers
    • Sealed Confidential hardware is optional and may run outside the EU only if you choose it

    Business Agent

    • Servers in Europe · GDPR
    • Your own isolated space, with separate storage for each customer
    • Never used for training; your content cannot surface in another customer’s answers
  5. You know what becomes of your documents

    By the hour
    When you disconnect, the machine and its disks are destroyed: download what you want to keep before you finish.
    Monthly plan
    Your document space stays encrypted for as long as you decide, and you can wipe it in one click. Each working session still starts clean.

Honesty. We don't promise "zero-knowledge": any system that processes data decrypts it in memory in order to work on it. What we promise is who can see it and for how long — and every line of that can be checked by an independent auditor.

In plain words

Your data, kept safe — in plain words

1

In a private box

Your documents locked in a space that is only yours.

2

Only you hold the key

No one else can open it. Not even us.

3

Destroyed when you finish

When your session ends, the box is gone. Nothing remains.

Bank-grade encryption, verifiable.

Certifications & compliance

Real status, no fake badges

GDPR Compliant Compliance (DPA + processing records)
HIPAA Attestation / BAA Where applicable (not a certification)
ISO 27001 Planned Certification path planned; not started
SOC 2 Type II Planned Certification path planned; not started
EU AI Act Assessment planned Compliance

Note: GDPR and HIPAA are not certifications. We will never display a badge we haven't earned.

Technical details

If you have an IT consultant, this is the part to forward to them.

Your data is encrypted at rest (LUKS) and in transit (TLS 1.3). In-memory processing lasts only as long as the individual request; swap and core dumps are disabled, and temporary files live in RAM only. Your content resides exclusively in your tenant's encrypted database, with retention you control; we never access it or record it in our logs. No operator of ours can see your data in the clear (only a break-glass procedure that is logged and reported to you). The system has no outbound connectivity.

The four "zeros"

Zero data egress

On-prem and air-gapped: your data never leaves your perimeter. Managed tiers (dedicated, EU-hosted): data stays in the EU under a DPA.

Zero third-party retention

No third party retains your prompts or documents.

Zero training

Models never learn from your content.

Zero public cloud

No calls to external providers, by default.

Technical security

Encryption

TLS 1.3 in transit, AES-256 (LUKS) at rest, encrypted backups.

Access

Mandatory MFA, RBAC, append-only audit logs with hash chaining.

Blocked egress

The system sends nothing to the outside world — and you can verify it yourself.

Isolation

Separate containers, databases, and keys for every customer.

Independent pen test and bug bounty: on the roadmap ahead of go-live. Vulnerability disclosure policy: security.txt.

Want the “Data Flow & Isolation” whitepaper?

We walk you through where your data lives, step by step. Start with 3 hours or request the technical document.

Start with 3 hours Talk to us

3 hours · $21 · Servers in Europe · GDPR · No subscription