Security
Your data stays yours. You can leave.
Certifications, residency, models, access control, personal data, reversibility, subprocessors. Everything is public. What is not yet certified has a date.
Certifications
A public calendar is better than silence.
- Roadmap SOC 2 Type II target 2027
- Roadmap ISO 27001 target 2027
- Certified GDPR product compliance
Data residency
EU · France · On-premise. You choose where data lives.
- European Union (region documented in the contract)
- France (sovereignty option)
- On-premise on your infrastructure
Models
No training on your data, contractually guaranteed.
- OpenAI — no training on customer data (provider commitment + NEXA contract)
- Anthropic (Claude) — no training by default on API data
- Mistral — EU option, no training on your business prompts
- Sovereign / on-premise models — data does not leave your perimeter
Access control
One enterprise identity, roles per ritual, a journal you can inspect.
- SSO (OAuth, SAML)
- SCIM
- Granular roles per ritual (operator, reviewer, approver)
- Audit logs
Personal data
Detection and filtering before execution. What must not enter does not enter.
- Personal-data detection upstream of the run
- Filtering and masking per ritual policy
- Journal of what was kept or discarded
SCR-FEAT-12
guardrails-pii.png
Détection de données personnelles avant exécution : champs signalés, action appliquée (masquage / blocage / alerte).
Reversibility
Full export, open formats, no technical lock-in.
- Export of runs, evidence, Vault patterns
- Open formats (JSON, CSV, Audit Pack PDF)
- No lock-in on the memory your experts capitalized
Subprocessors
Public list of subprocessors and their role.
- EU cloud hosting — platform execution
- LLM engine providers — inference only, no training on your data
- Marketing-site host — public pages and forms
Talk security with us.
An IT framing call: residency, SSO, export, certification roadmap.