Security

Secure by design, sovereign by default.

Your knowledge stays yours. EU infrastructure, EU-hosted models, permissions at fact level, and an audit trail you can read.

  • GDPRCompliant
  • EU AI ActBy design
  • ISO 27001In progress

01 — Ownership

Your knowledge stays yours.

The knowledge base is an asset you own, not a service you rent.

  1. No data training

    Your data is never used to train models. Guaranteed in writing, in every contract.

  2. Full export, any time

    The knowledge base leaves in open formats, readable by people: pages, facts and sources, not embeddings.

  3. Deletion propagates

    When you remove a source, everything derived from it is removed as well: summaries, answers, and graph entries.

02 — Knowledge protection

Sensitive data never reaches a model that shouldn’t see it.

Most AI tools send whatever they retrieve into the prompt. graphzero decides what a model may see before inference runs.

  1. Sensitive-data masking

    Fields marked sensitive — salaries, IBANs, health data — never appear in a prompt. The system can use them to find the answer; the model never sees them.

  2. Sensitive-data rerouting

    Content too sensitive for external inference is processed by an EU-hosted or self-hosted model instead. Decided per query, from how the data is tagged.

  3. Permissions at fact level

    Access rights from SharePoint, Drive and your other sources hold inside graphzero. Every answer is computed against the asker’s rights, and a group channel sees only what every member may see.

  4. Derived knowledge inherits its sources

    A summary built from three documents is visible only to someone who may open all three. Revoke one source, and the answers built on it follow.

03 — Governance

Managed in one place.

Without a knowledge layer, employees connect tools to assistants one by one, with whatever rights the OAuth screen granted. Nobody can list what is connected, and data becomes accessible that shouldn’t be.

  1. One connection per source

    HubSpot, Salesforce, AFAS or DATEV is connected once, to graphzero by your admin — not by every employee into their assistants.

  2. Scoped centrally

    Which teams reach which source, read-only or read-write, is decided by the admin, applied everywhere, changed in one place.

  3. Full audit trail

    What was retrieved, by whom, and when. Every shared answer carries a record of what it rests on.

04 — Jurisdiction

European, enforced.

  1. Hosted in EU

    Your knowledge base runs on European infrastructure, and EU-hosted models process your content inside the EU.

  2. Checked at runtime

    If a configured model doesn’t meet the requirements set for your data, the pipeline stops. It fails closed, not with a warning.

  3. EU AI Act

    You always know you are talking to AI. No emotion recognition, no ranking of people, no individual-level analytics.

  4. Works-council ready

    Consent per team, no individual usage statistics, and a works-agreement template aligned with German co-determination.

05 — Deployment

Pick your deployment.

  • Multi-tenant cloud

    Our shared environment on EU infrastructure. The quickest way to start, under the same residency and access rules.

    EU infrastructure · shared

  • Dedicated single-tenant

    Your own isolated environment on EU infrastructure, operated by us.

    EU infrastructure · dedicated

  • Bring your own cloud

    Runs in your cloud account, in your region, under your controls.

    your cloud · your region

  • On-premise

    On request: graphzero inside your own data centre, on hardware you control.

    your data centre

06 — Inference

Pick your inference.

  • EU-hosted models

    Your content is processed inside the EU.

  • Self-hosted models

    Open-weight models running beside the index, in whichever runtime you choose.

  • Your own keys

    Inference on your existing model agreements — AI spend stays on your contract, at your negotiated terms.

Combinations are supported: routine tasks on self-hosted models, sensitive content stripped before anything external.

07 — Assurance

Certifications & assessments.

  • GDPR

    Compliant

    DPA, sub-processor list, TOMs and transfer impact assessment available on request.

  • EU AI Act

    Compliant by design

    You always know you’re talking to AI, and nothing here ranks or profiles people.

  • ISO 27001

    In progress

    Certification underway; our security management system follows the standard today.

  • ISO 42001 — AI management

    In preparation, following 27001.

    In preparation

  • CASA

    Google application security assessment, for Google Workspace connections.

    In progress

  • Penetration testing

    Independent, before each major release; summary under NDA.

    Per release