Our security guarantees
EU hosting
Your data stays in the European Union, under European law, outside the reach of the CLOUD Act and non-EU jurisdictions.
Daily wipe
Processing servers are reset every night: no data persists on the GPU from one day to the next. Structural minimisation.
Encryption & VPN tunnel
Encrypted traffic and access through a WireGuard VPN tunnel: exchanges between your users and the AI are protected end to end.
SSO authentication
Login through your existing directory (SSO): centralised access management, no extra password, immediate revocation.
No vendor leakage
No data is sent to a third-party AI provider or reused to train a model. The model runs on infrastructure you control.
Auditable open source
Open-source components, no proprietary black box: every part is verifiable, replaceable and reversible.
Monitoring & backups
Observability (Grafana & Prometheus), automatic alerting, daily backups and automatic failover on incident.
Per-organisation isolation
Your knowledge bases and histories stay within your perimeter, partitioned, never pooled with other clients.
Regulatory compliance
RGPD (GDPR)
We provide the documentation for your DPO: support for the data protection impact assessment (DPIA), legal basis, minimisation, and an erasure procedure, including the vectors held in a RAG system.
AI Act
We help you place your use case within the risk tiers of the European regulation and prepare the obligations and deadlines, including the fundamental rights impact assessment required of public bodies.
Frameworks & hosting
Depending on how sensitive your data is, we design the hosting to meet the relevant security frameworks. Architecture and hosting provider are adapted to your compliance requirement.
SecNumCloud (ANSSI)
The French qualification framework for trusted cloud offerings, for the most sensitive data.
HDS : health data
Certified Health Data Hosting, required for processing in the medical sector.
ISO/IEC 27001
Information security management: governance, risk management and continuous improvement.
The hosting provider and level of qualification are defined together during scoping, based on the nature of your data.
A specific security requirement?
Let's talk about your regulatory constraints and the architecture that fits your data.
Book a demo