Security & Trust

Your data, handled the way you'd handle it yourself.

Bringing AI into a real business process means trusting it with real information. We're an Austrian company operating under EU data protection law — and we'd rather tell you exactly what we do and don't do today than hide behind badges we haven't earned.

Austria-based · EU processing by defaultEncrypted in transit & at restNever used to train shared models
01 — The questions you should be asking

Straight answers to the questions your security team will ask.

No hand-waving and no jargon wall. Here is how your data is actually handled — and where the answer is “it depends,” we tell you what it depends on.

Where is your data processed?

We're an Austrian company, so EU data protection is our home ground — processing location is a decision we make with you at the start of a project, not something we impose.

  • As a default we process within the EU, on infrastructure in EU regions — Austria included where you want data kept in-country.
  • Under Austrian and EU law (GDPR, DSG), your data stays governed by European rules, not exported to weaker regimes.
  • Where a workload has to run elsewhere, we tell you exactly where and why before anything moves — and the processing region is written into the project setup, not left to chance.

How is your data stored?

Data is encrypted in transit and at rest, and we store as little of it as the job actually needs.

  • Transport is secured with TLS; stored data is encrypted at rest.
  • We separate each client's data — one customer's records are never mixed into another's.
  • Wherever a result can be produced without keeping the raw input, we don't keep the raw input.

Who can see it?

Access is scoped to the people who genuinely need it, and every one of those people is accountable.

  • Your data is visible to your authorised users under the roles you define.
  • On our side, access is limited to the specific engineers working on your system, and only when there's a reason.
  • We don't browse client data. Any access for support or debugging is deliberate, logged, and agreed with you.

How long does it stay?

Retention is a rule you set, not a default we hide. When the retention window ends, data is deleted.

  • Retention periods are defined per data type together with you during setup.
  • When a period expires, the data is removed on a schedule — it doesn't linger indefinitely.
  • You can request deletion of specific records or a full export at any time.

Can models be trained on your data?

No — not unless you explicitly ask us to, for your own benefit. Your data is not training fuel.

  • By default, your content is never used to train shared or public models.
  • We select external AI providers on the basis that they do not train on data sent through their API.
  • If a private model tuned on your own data would help you, that's a separate, opt-in project — your data, your model, isolated to you.

How do permissions work?

Role-based access control: every user gets exactly the rights their role needs, and nothing more.

  • Roles define who can view, edit, approve and export — mapped to how your organisation actually works.
  • Sensitive actions can require a second person to approve them.
  • Permissions can mirror your existing identity provider so you manage people in one place.

Is there logging?

Yes. Meaningful actions are recorded, so there's always an answer to 'who did what, and when.'

  • Access, changes and approvals are captured in an audit trail.
  • Every AI-generated output can be traced back to the input it came from.
  • Logs are available to your administrators for review and export.

How are external AI services used?

We're upfront about which parts of a system use third-party AI, and we choose those providers carefully.

  • Where we use an external model, we tell you which provider and for what purpose.
  • We only work with providers whose terms prohibit training on the data you send them.
  • For workloads that can't leave your environment, we can run open models on infrastructure you control instead.

What hosting options exist?

Hosting is flexible because security requirements aren't one-size-fits-all.

  • Managed cloud in an EU region, including Austrian data centres — the fastest way to start.
  • Your own cloud tenant, so the data never leaves your account.
  • On-premise or private deployment for the most sensitive environments, decided per project.

How are sensitive recordings handled?

Camera and voice input is treated as the sensitive material it is — captured deliberately, kept only as needed.

  • Recording is intentional and visible to the wearer, not silent or always-on.
  • Where the useful result is the structured output, the underlying photo or audio can be discarded after processing.
  • Faces, bystanders and other details not relevant to the task can be blurred or excluded by policy.
02 — Where we honestly stand

We'd rather be honest than wave a badge we haven't earned.

As a young Austrian company, we operate under EU data protection law from day one, and we don't claim certifications we don't hold. What we can tell you is exactly which standards we build against, what's already in place, and what we implement per project for enterprise clients — so you can judge us on substance, not stickers.

Standards we build against

Frameworks we design and engineer to, whether or not we're formally certified yet.

  • GDPR and Austrian data protection law (DSG) for how personal data is processed, stored and deleted
  • Encryption in transit (TLS) and at rest as a baseline, not an add-on
  • Principles behind ISO 27001 and SOC 2 — least privilege, separation, auditability
  • Data minimisation: keeping the result, not the raw material, wherever possible

Already in place today

Measures that are live right now, on every system we build.

  • Per-client data isolation, so no customer's data mixes with another's
  • Role-based access control with an audit trail of access, changes and approvals
  • EU-region processing as the default, with Austrian in-country hosting available
  • External AI providers chosen on no-training-on-your-data terms
  • Human approval gates before anything irreversible happens

Delivered per project

Enterprise requirements we implement as part of the engagement when you need them.

  • On-premise or private-cloud deployment for the most sensitive environments
  • Single sign-on and integration with your existing identity provider
  • Custom retention, deletion and data-residency rules written into the build
  • Formal security reviews, questionnaires and DPAs handled as part of onboarding
  • Dedicated private models tuned on your own isolated data, when it helps you

If your procurement process requires a specific certification or a signed security agreement, tell us early — we'll be straight about what we hold today and what we can commit to putting in place for your project.

Bring us your requirements

Send us your security questionnaire.

The fastest way to know whether we fit your requirements is to put them in front of us. Share your security, data-residency and compliance needs and we'll answer each one plainly — what's already covered, and what we'd implement for your deployment.