Trust centre
Governance by architecture, not by policy.
A promise not to keep your documents is worth less than a system that cannot. Here is how retrieval, encryption, identity and inference are actually wired — including the part we cannot yet claim.
Architecture
What happens to a document when you ask a question.
Files are fetched from your cloud at query time, held in memory while the answer is composed, and dropped when the response is sent. What persists is a lightweight index — vector embeddings and classification labels — never the file itself.
Everything in transit uses TLS 1.3; OAuth tokens are encrypted at rest with AES-256-GCM. Each organisation runs in its own scope — queries, document access and metadata are partitioned with no cross-tenant path.
You sign in through Google or Microsoft, so we never see or store a password. SSO is available for organisations with central identity management, and TOTP two-factor is available on every account.
Each document access is recorded with user, timestamp and action. Administrators can review the trail, see what is indexed, watch query patterns and export logs for a compliance review. Sensitivity classification runs automatically at index time.
Inference is distributed across four providers — Groq, Google Gemini, OpenAI and Anthropic. All four contractually exclude API data from training, and Zero Data Retention is enabled on every one, so no query data persists beyond the immediate response.
Data protection
GDPR-native, not GDPR-adapted.
AiSU Strata Oy is a Finnish company processing within EU infrastructure, so the regulation is the starting point rather than a retrofit. A Data Processing Agreement is available on request. Access, rectification and erasure requests are supported end to end — on erasure, account data, document metadata, index entries and conversation history are all permanently deleted.
Compliance
Framework alignment, stated precisely.
Mapped means our controls are documented against the framework. It does not mean audited or certified, and we will not imply otherwise — ask and we will send the gap list.
SOC 2 Type II
MappedControls mapped against the Trust Services Criteria: 28 of 33 Security, 3 of 3 Availability, 4 of 4 Confidentiality. Not yet audited — mapping, not attestation.
ISO 27001:2022
Mapped78 of 93 Annex A controls implemented and documented. Certification is not claimed; the gap list is available on request.
GDPR
CompliantArticle-by-article mapping, EU processing, DPA on request, and data subject rights served through the API.
EU AI Act
PlannedArticle 50 transparency obligations apply from 2 Aug 2026. High-risk (Annex III) obligations are deferred to 2 Dec 2027 under the 2026 Digital Omnibus. Conformity documentation is being prepared.
Read our Article 50 transparency postureDocumentation
Fourteen governance documents.
Effective since February 2026, available to prospects and customers on request.
Transparency
Sub-processors, including the awkward part.
Your documents never leave the EU cloud storage you already control. We retrieve the relevant excerpts at query time, process them in memory and discard them after each response. Nothing is copied into our infrastructure.
At inference time those excerpts transit US-based LLM providers under Zero Data Retention: processed transiently, never stored, never logged for training.
US inference providers are in the path today. Because nothing is persisted, we add no new place your data comes to rest — but that is a different guarantee from keeping processing inside your jurisdiction, and we will not blur the two.
EU-based inference, bring-your-own-model and a self-hosted deployment are all on the roadmap. If sovereignty is a hard requirement today, talk to us and we will be straight about timelines.
Regions reflect the configuration in force on 30 July 2026. We publish this list and give fourteen days' notice before a sub-processor changes.
Send this to your security reviewer.
DPA template, sub-processor list, framework mappings and the gap list — or half an hour with the person who built it.