Private by design, in every layer.
Your documents and application data are stored and hosted in the European Union, in the Frankfurt region.
We use Google Vertex AI for analysis. Under Google's Vertex AI terms, your content is not used to train Google's models, and never trains ours.
Every organisation is a sealed tenant. Users in one organisation can never reach another organisation's data.
All data is encrypted in transit with TLS and at rest with AES-256, across every service and data store.
Our GDPR compliance has been reviewed and confirmed by an independent third-party auditor.
Single sign-on with granular, role-based permissions, down to individual projects, managed by your admins.
Verified GDPR compliance
An independent third party has audited Arctis AI and confirmed our compliance with the EU General Data Protection Regulation. The measures described below are the technical and organisational controls behind that result.
Recognised standards & regulations
Independently audited by a third party for compliance with EU data-protection law.
Aligned with its core principles: transparency about AI use and meaningful human oversight.
The entire platform runs on ISO 27001-certified cloud infrastructure.
Every core provider we rely on is independently SOC 2 Type II audited.
Cloud infrastructure attested to Germany's C5 cloud-computing security standard.
Stored and hosted exclusively in the EU (Frankfurt), with no transfer to third countries.
Everything runs in the European Union
Your data does not leave the EU for storage or hosting. The entire Arctis AI platform is operated in the Frankfurt region.
We build on managed European cloud infrastructure so that data residency, patching, and physical security are handled by providers held to independent standards, while access to your data stays strictly governed by the controls in this document.
The underlying data centres are operated by hyperscale providers (AWS and Google Cloud) that maintain their own independent certifications, including ISO 27001, SOC 2 and BSI C5. These attestations cover the physical and infrastructure layer beneath Arctis AI.
How AI uses your data
Arctis AI performs all AI analysis through Google Vertex AI, Google's enterprise AI platform, not the consumer Gemini app or its free API.
This distinction matters. Under Google's Vertex AI terms, the prompts and documents we send for analysis are not used to train or improve Google's foundation models. Your content is processed to produce your result, and that is all.
Arctis AI likewise does not train, fine-tune, or build any model on your data. There is no shared model that learns from one customer and benefits another. Analysis runs strictly within your organisation's context, and outputs stay inside your tenant.
Arctis AI supports expert judgment rather than replacing it, in keeping with the EU AI Act's emphasis on transparency and human oversight.
To keep analysis reliable we monitor AI quality through Langfuse. Email addresses are automatically redacted from these diagnostics before they are recorded.
Neither Google (per Vertex AI terms) nor Arctis AI trains models on your content.
Vertex AI is accessed with dedicated service credentials, not a shared consumer product.
Your data never trains a shared model or informs another customer's results.
Email addresses are redacted from quality diagnostics.
Access control & permissions
Access to Arctis AI is governed by enterprise single sign-on and a layered permission model that follows the principle of least privilege.
Sign-in runs through WorkOS, our enterprise identity provider. Every session carries a cryptographically signed token, verified on each request against the provider's public keys. The organisation a session belongs to is itself a signed claim. It cannot be forged or swapped by a client.
On top of organisation membership, access is granted per project. Administrators assign each member an Editor or Viewer role, and those grants cascade automatically through nested project structures. Members start with no access until it is explicitly granted.
Changes take effect immediately. When an administrator revokes access or changes a role, the new permissions apply on the very next request. There is no waiting for a session to expire.
You must belong to the organisation, the multi-tenancy boundary.
Granted per project by admins; cascades to sub-projects and their documents.
A final defence-in-depth check enforced inside the database itself.
Each organisation is fully isolated
Multi-tenant separation is enforced on every request, at two independent layers.
Every record (projects, documents, extracted facts) is tied to an organisation. Each request is checked against your organisation on the server before any data is returned.
Cross-organisation access is blocked at the application layer and again by database row-level security policies, so a single mistake in one layer cannot expose another tenant's data.
Preview and testing environments run on their own isolated databases. Your production data is never copied into them.
Encrypted in transit and at rest
Data is protected both while it moves and while it is stored.
Every connection between your browser, our services, and our data stores is secured with TLS. Documents and database contents are encrypted at rest with AES-256 by the underlying managed platforms.
Credentials never live in our source code. Secrets are held in managed secret stores and separated by environment, so staging and production run on entirely different keys.
TLS / HTTPS on every service-to-service and client connection.
AES-256 on the database and on document storage.
No secrets in code; managed vaults, isolated per environment.
Secure development & operations
Our development process is designed to keep unsafe changes out of production and to contain what the AI is allowed to do.
Every change is peer-reviewed before release, supported by automated review assistants that flag issues early.
Linting, formatting and database-migration safety checks run on every change and block anything unsafe from merging.
When analysis requires running code, it executes in an isolated, ephemeral sandbox kept separate from our core systems.
Per-organisation rate limits and strict cross-origin controls validate the exact origin of every request.
Third-party dependencies are version-pinned and reviewed, with pre-merge checks on every commit.
Application-level checks are backed by database row-level security, so no single layer is the only thing standing between tenants.
Ownership, retention & deletion
You remain the owner of everything you upload. Arctis AI processes it on your behalf, and only for the purpose of serving you.
Deleting a project or document removes it from all views immediately. A recovery window protects you against accidental deletion, and permanent erasure is available on request.
Because our GDPR compliance has been independently audited, the processes behind these rights (access, deletion and erasure) are documented and externally reviewed rather than merely asserted.
Arctis AI acts as processor; you remain the controller of your data.
Immediate removal from view, with a recovery window against mistakes.
Permanent deletion available when you ask for it.
The services we rely on and why
We work with a small, deliberate set of established providers. Each one has a specific role and sees only what it needs to perform it.
Every provider is a recognised platform with independently audited security certifications. The majority hold both SOC 2 Type II and ISO 27001, and all are GDPR-compliant.
| Provider | Purpose | What it processes | Independent certifications |
|---|---|---|---|
Supabase EU · Frankfurt | Database & document storage | Your uploaded documents and structured analysis data. | SOC 2 Type IIISO 27001HIPAAGDPR |
Render EU · Frankfurt | Application hosting (backend) | Processes requests; holds no data of its own at rest. | SOC 2 Type IIISO 27001GDPR |
Vercel EU · Frankfurt | Web application hosting | Serves the user interface; no document storage. | SOC 2 Type IIISO 27001GDPR |
Google Vertex AI | AI analysis | Document and prompt content, processed transiently and not retained to train models. | ISO 27001SOC 2BSI C5GDPR |
Langfuse EU · Frankfurt | AI quality monitoring | AI request diagnostics, with email addresses redacted. | SOC 2 Type IIISO 27001GDPR |
WorkOS EU · Frankfurt | Identity & single sign-on | User identity and organisation membership. | SOC 2 Type IIHIPAAGDPR |
Resend EU · Frankfurt | Transactional email | Addresses and content for notification emails. | SOC 2 Type IIGDPR |