Skip to content

Trust centre

Governance by architecture, not by policy.

A promise not to keep your documents is worth less than a system that cannot. Here is how retrieval, encryption, identity and inference are actually wired — including the part we cannot yet claim.

Posture at a glanceUpdated 31 Jul 2026
Your documents stored by usNone, ever
Used to train a modelNo — all four providers
Company and hostingFinnish · EU infrastructure
Inference providers todayUS, zero retention
Governance documents14, on request

Architecture

What happens to a document when you ask a question.

01 · AskYour questionScoped to your own permissions before anything is fetched.
02 · RetrieveExcerpts, from your cloudRead live over TLS 1.3 from the storage you control.
03 · AnswerComposed in memoryInference under zero retention, citations attached per sentence.
04 · DiscardExcerpts droppedOnly the access log and the search index remain.
Transient processingNothing stored

Files are fetched from your cloud at query time, held in memory while the answer is composed, and dropped when the response is sent. What persists is a lightweight index — vector embeddings and classification labels — never the file itself.

Document copies keptNone
Held in memory forThe length of one query
PersistedEmbeddings + labels only
Encryption and isolationTLS 1.3 · AES-256-GCM

Everything in transit uses TLS 1.3; OAuth tokens are encrypted at rest with AES-256-GCM. Each organisation runs in its own scope — queries, document access and metadata are partitioned with no cross-tenant path.

In transitTLS 1.3
Tokens at restAES-256-GCM
Tenant modelPer-organisation scope
AuthenticationOAuth 2.0 · SSO · TOTP

You sign in through Google or Microsoft, so we never see or store a password. SSO is available for organisations with central identity management, and TOTP two-factor is available on every account.

Passwords heldNone
SSOAvailable
Two-factorTOTP, all plans
Audit and governanceEvery access logged

Each document access is recorded with user, timestamp and action. Administrators can review the trail, see what is indexed, watch query patterns and export logs for a compliance review. Sensitivity classification runs automatically at index time.

Log granularityPer document access
ExportCSV or API
ClassificationAutomatic at indexing
AI provider governanceZero Data Retention

Inference is distributed across four providers — Groq, Google Gemini, OpenAI and Anthropic. All four contractually exclude API data from training, and Zero Data Retention is enabled on every one, so no query data persists beyond the immediate response.

ProvidersGroq · Gemini · OpenAI · Anthropic
Training on your dataContractually excluded
RetentionZero, every provider

Data protection

GDPR-native, not GDPR-adapted.

AiSU Strata Oy is a Finnish company processing within EU infrastructure, so the regulation is the starting point rather than a retrofit. A Data Processing Agreement is available on request. Access, rectification and erasure requests are supported end to end — on erasure, account data, document metadata, index entries and conversation history are all permanently deleted.

Article-by-article mapping
Data minimisationArt. 5(1)(c)
Purpose limitationArt. 5(1)(b)
Right of accessArt. 15
Right to rectificationArt. 16
Right to erasureArt. 17
Right to data portabilityArt. 20
Data protection by designArt. 25
Records of processingArt. 30

Compliance

Framework alignment, stated precisely.

Mapped means our controls are documented against the framework. It does not mean audited or certified, and we will not imply otherwise — ask and we will send the gap list.

SOC 2 Type II

Mapped

Controls mapped against the Trust Services Criteria: 28 of 33 Security, 3 of 3 Availability, 4 of 4 Confidentiality. Not yet audited — mapping, not attestation.

ISO 27001:2022

Mapped

78 of 93 Annex A controls implemented and documented. Certification is not claimed; the gap list is available on request.

GDPR

Compliant

Article-by-article mapping, EU processing, DPA on request, and data subject rights served through the API.

EU AI Act

Planned

Article 50 transparency obligations apply from 2 Aug 2026. High-risk (Annex III) obligations are deferred to 2 Dec 2027 under the 2026 Digital Omnibus. Conformity documentation is being prepared.

Read our Article 50 transparency posture

Documentation

Fourteen governance documents.

Effective since February 2026, available to prospects and customers on request.

Information Security Policy
Data Processing Agreement (DPA)
Record of Processing Activities (ROPA)
Data Protection Impact Assessment (DPIA)
Privacy Policy
Terms of Service
Acceptable Use Policy
Sub-Processor List
Data Breach Procedure
Legitimate Interest Assessments
Cookie Policy
Responsible Disclosure Policy
Retention Schedule
Vendor Risk Assessment

Transparency

Sub-processors, including the awkward part.

Where your data is processed

Your documents never leave the EU cloud storage you already control. We retrieve the relevant excerpts at query time, process them in memory and discard them after each response. Nothing is copied into our infrastructure.

At inference time those excerpts transit US-based LLM providers under Zero Data Retention: processed transiently, never stored, never logged for training.

What we will not claimThis is not data sovereignty.

US inference providers are in the path today. Because nothing is persisted, we add no new place your data comes to rest — but that is a different guarantee from keeping processing inside your jurisdiction, and we will not blur the two.

EU-based inference, bring-your-own-model and a self-hosted deployment are all on the roadmap. If sovereignty is a hard requirement today, talk to us and we will be straight about timelines.

ProviderPurposeRegionTrains?
GroqLLM inference · simple queriesUSNo
Google (Gemini)LLM inference · simple to moderateUSNo
OpenAILLM inference · moderate to complexUSNo
AnthropicLLM inference · complexUSNo
TavilyWeb search augmentationUSNo
Murf AIText-to-speech synthesisUSNo
RenderApplication hostingEU
CloudflareEdge hosting & request gatewayGlobal
StripePayment processingEU / US

Regions reflect the configuration in force on 30 July 2026. We publish this list and give fourteen days' notice before a sub-processor changes.

Send this to your security reviewer.

DPA template, sub-processor list, framework mappings and the gap list — or half an hour with the person who built it.

Read the platform page

We use essential cookies to run this site. With your consent, we also use analytics cookies to understand how visitors use it so we can improve the experience. You can change your choice anytime in the cookie policy. Read our cookie policy