Data security
In many companies the biggest risk shows up before any rollout: staff paste company data into personal, free AI chats because nobody gave them a better tool. Working with us puts that in order. These are the rules we follow on every project.
You get the same rules in writing with our offer. Each one can be checked.
We use paid services under contract. Your data is not used to train AI models.
The system sees only the data its task requires. Where reading is enough, it cannot write.
An email to a customer, a record in a company system, any irreversible action: a named person approves it, not the AI.
If the AI does not need to see names or numbers, we mask them before the data reaches the model.
Passwords and access keys live in an encrypted vault, separately for each client. They never go into emails or code.
Emails, web pages and attachments from strangers cannot give the system instructions. We protect it against manipulation attempts (prompt injection, the number one risk on the OWASP Top 10 for AI applications).
Every action the system takes is recorded. You always know what happened, when, and on whose instruction.
Data is backed up automatically and changes can be rolled back. A failure does not mean lost data.
When our work ends, we remove all our access and delete the data. We confirm it in writing.
Three options, chosen according to the data the system handles. We agree on it before the quote.
Data stored and processed on servers in the European Union. The fastest rollout.
Data stays in the company. Only what is strictly needed goes to external AI, without personal data.
Database and AI model on a server in your company. For data that must not leave the building, such as medical records.
Signed together with the main contract, with a list of sub-processors.
Voice and chat assistants tell people they are talking to AI, as the AI Act requires.
For companies covered by NIS2 rules we provide the information needed to assess us as a supplier.
What we do not promise: one hundred percent security. Nobody can honestly guarantee that. We promise the risk is kept to a minimum and every principle above can be checked.
No. We only use business versions of AI services whose contracts exclude training on customer data.
Yes. You can choose an EU cloud, a hybrid setup or a full installation on a server in your company.
Not without a person’s approval. Any outgoing or irreversible action is approved by a named person.
We sign a data processing agreement together with the main contract, including a list of sub-processors.
No honest supplier can give a one hundred percent guarantee. We promise the risk is kept to a minimum and each of the nine principles can be checked.
If those are personal, free accounts, yes: in many companies that is the biggest risk today. A company tool with clear rules is safer than a ban nobody follows.
Tell us what data the system will handle and we will propose a setup and access rules. All in writing, before the quote.