Security and data

Your data stays in the EU, and the line between companies is in the database

Not a policy somebody wrote, but a boundary that lives in storage — and a switch that has to be turned on before anything is processed outside the EU.

How it is set up

  • Storage in the EU

    The database runs in a European region. So do the mirrors of your source systems.

  • AI in the EU

    The models run on Vertex AI in a European region. Leaving the EU needs its own switch, and it is off.

  • Separation between companies

    Every row belongs to a company, and access is enforced in the query — not in the screen.

  • Roles and modules

    What a user may see, and what the company has enabled, are two independent switches.

  • Audit trail

    Changes are recorded with who, when and what the row was before — searchable, not a log file.

  • No long-lived keys on the machines

    Services fetch an identity at runtime instead of carrying a key that can leak.

Why "in the EU" is not enough as a sentence

Most vendors can say data is stored in the EU. The question that decides anything is what happens when an AI model reads it.

Here the answer is that the models also run in a European region, and that the way out of the EU is a configuration set deliberately per environment. If you want to see how it is wired, we will show you.

Questions we get from IT

Where does it run?

On our own infrastructure in the EU, with the database as a managed service in a European region. We are happy to walk your IT team through the setup.

Can one customer see another customer's data?

No. Company membership sits on the row and is enforced in the query, not in the interface. That applies to the AI agent too, which inherits the user's permissions.

What happens to our data if we leave?

It is yours. The source systems still hold it, and what was created in Workspace can be exported. We do not build lock-in as a business model.

Is our data used to train models?

No.

Bring your head of IT

We go through architecture, permissions and data processing in detail.

We'd like to use one cookie to recognise your browser between visits, so we understand where our visitors come from. No ad networks, no sharing — only our own measurement. There is more in the privacy policy in the footer.