Our security guarantees
EU hosting
Your data stays in the European Union, under European law, outside the reach of the CLOUD Act and non-EU jurisdictions.
Daily wipe
Processing servers are reset every night: no data persists on the GPU from one day to the next. Structural minimisation.
Encryption & VPN tunnel
Encrypted traffic and access through a WireGuard VPN tunnel: exchanges between your users and the AI are protected end to end.
SSO authentication
Login through your existing directory (SSO): centralised access management, no extra password, immediate revocation.
No vendor leakage
No data is sent to a third-party AI provider or reused to train a model. The model runs on infrastructure you control.
Auditable open source
Open-source components, no proprietary black box: every part is verifiable, replaceable and reversible.
Monitoring & backups
Prometheus observability with GPU and inference probes, metrics kept on your own infrastructure. Backups and alerting policy defined with you during scoping.
Per-organisation isolation
Your knowledge bases and histories stay within your perimeter, partitioned, never pooled with other clients.
Architecture & operations
"Operated for you" is not a sales line, it is a software layer. Here is what it actually does, and what your IT department can verify.
Self-hosted monitoring
Prometheus, a system exporter and the NVIDIA DCGM exporter, with dedicated probes on the inference engine, the embedding service and GPU load. Metrics stay on your infrastructure: no telemetry is sent to any third-party observability service.
Scheduled shutdown, automated
Stopping and restarting GPU instances is driven by the deployment layer, not by a manual step. That is what makes it practical to pay for compute during working hours only.
Interchangeable host
Provisioning, start and stop all go through a common interface that is independent of the GPU provider. Changing host does not mean rewriting the deployment: this is reversibility applied to infrastructure.
Closed network access
The WireGuard tunnel is provisioned by script, on the server side as well as on the client machine. Access to the AI is not exposed on the public internet.
Separate components
Authentication, database, embedding service, inference engine and model management are distinct components. Each can be audited, updated or replaced without touching the others.
Reproducible deployment
The installation is described in versioned code, not in a manual runbook. The same deployment can be replayed identically, which makes the infrastructure verifiable and transferable.
Regulatory compliance
GDPR (GDPR)
We provide the documentation for your DPO: support for the data protection impact assessment (DPIA), legal basis, minimisation, and an erasure procedure, including the vectors held in a RAG system.
AI Act
We help you place your use case within the risk tiers of the European regulation and prepare the obligations and deadlines, including the fundamental rights impact assessment required of public bodies.
Frameworks & hosting
Depending on how sensitive your data is, we design the hosting to meet the relevant security frameworks. Architecture and hosting provider are adapted to your compliance requirement.
SecNumCloud (ANSSI)
The French qualification framework for trusted cloud offerings, for the most sensitive data.
HDS : health data
Certified Health Data Hosting, required for processing in the medical sector.
ISO/IEC 27001
Information security management: governance, risk management and continuous improvement.
The hosting provider and level of qualification are defined together during scoping, based on the nature of your data.
A specific security requirement?
Let's talk about your regulatory constraints and the architecture that fits your data.
Book a demo