Security
Secure by design, sovereign by default.
Your knowledge stays yours. EU infrastructure, EU-hosted models, permissions at fact level, and an audit trail you can read.
Compliant
By design
In progress
01 — Ownership
Your knowledge stays yours.
The knowledge base is an asset you own, not a service you rent.
No data training
Your data is never used to train models. Guaranteed in writing, in every contract.
Full export, any time
The knowledge base leaves in open formats, readable by people: pages, facts and sources, not embeddings.
Deletion propagates
When you remove a source, everything derived from it is removed as well: summaries, answers, and graph entries.
02 — Knowledge protection
Sensitive data never reaches a model that shouldn’t see it.
Most AI tools send whatever they retrieve into the prompt. graphzero decides what a model may see before inference runs.
Sensitive-data masking
Fields marked sensitive — salaries, IBANs, health data — never appear in a prompt. The system can use them to find the answer; the model never sees them.
Sensitive-data rerouting
Content too sensitive for external inference is processed by an EU-hosted or self-hosted model instead. Decided per query, from how the data is tagged.
Permissions at fact level
Access rights from SharePoint, Drive and your other sources hold inside graphzero. Every answer is computed against the asker’s rights, and a group channel sees only what every member may see.
Derived knowledge inherits its sources
A summary built from three documents is visible only to someone who may open all three. Revoke one source, and the answers built on it follow.
03 — Governance
Managed in one place.
Without a knowledge layer, employees connect tools to assistants one by one, with whatever rights the OAuth screen granted. Nobody can list what is connected, and data becomes accessible that shouldn’t be.
One connection per source
HubSpot, Salesforce, AFAS or DATEV is connected once, to graphzero by your admin — not by every employee into their assistants.
Scoped centrally
Which teams reach which source, read-only or read-write, is decided by the admin, applied everywhere, changed in one place.
Full audit trail
What was retrieved, by whom, and when. Every shared answer carries a record of what it rests on.
04 — Jurisdiction
European, enforced.
Hosted in EU
Your knowledge base runs on European infrastructure, and EU-hosted models process your content inside the EU.
Checked at runtime
If a configured model doesn’t meet the requirements set for your data, the pipeline stops. It fails closed, not with a warning.
EU AI Act
You always know you are talking to AI. No emotion recognition, no ranking of people, no individual-level analytics.
Works-council ready
Consent per team, no individual usage statistics, and a works-agreement template aligned with German co-determination.
05 — Deployment
Pick your deployment.
Multi-tenant cloud
Our shared environment on EU infrastructure. The quickest way to start, under the same residency and access rules.
EU infrastructure · shared
Dedicated single-tenant
Your own isolated environment on EU infrastructure, operated by us.
EU infrastructure · dedicated
Bring your own cloud
Runs in your cloud account, in your region, under your controls.
your cloud · your region
On-premise
On request: graphzero inside your own data centre, on hardware you control.
your data centre
06 — Inference
Pick your inference.
EU-hosted models
Your content is processed inside the EU.
Self-hosted models
Open-weight models running beside the index, in whichever runtime you choose.
Your own keys
Inference on your existing model agreements — AI spend stays on your contract, at your negotiated terms.
Combinations are supported: routine tasks on self-hosted models, sensitive content stripped before anything external.
07 — Assurance
Certifications & assessments.

GDPR
Compliant
DPA, sub-processor list, TOMs and transfer impact assessment available on request.

EU AI Act
Compliant by design
You always know you’re talking to AI, and nothing here ranks or profiles people.

ISO 27001
In progress
Certification underway; our security management system follows the standard today.
ISO 42001 — AI management
In preparation, following 27001.
In preparation
CASA
Google application security assessment, for Google Workspace connections.
In progress
Penetration testing
Independent, before each major release; summary under NDA.
Per release
