How Arctis AI protects your data
Arctis AI analyses your most sensitive documents. This overview sets out the technical and organisational measures that keep that data private, isolated, and under your control, hosted in the European Union, and never used to train AI models.
Private by design, in every layer.
Recognised standards and regulations
Arctis AI is built for compliance with the EU General Data Protection Regulation: documented measures, an Art. 28 data-processing agreement, a maintained sub-processor list, and defined processes for data-subject rights. Our own ISO 27001 certification is currently in progress.
Everything runs in the European Union
Your data does not leave the EU for storage or hosting. The entire Arctis AI platform is operated in the Frankfurt region.
We build on managed European cloud infrastructure so that data residency, patching, and physical security are handled by providers held to independent standards, while access to your data stays strictly governed by the controls in this document.
The underlying data centres are operated by hyperscale providers (AWS and Google Cloud) that maintain their own independent certifications, including ISO 27001, SOC 2 and BSI C5.
How AI uses your data
Arctis AI performs all AI analysis through Google Vertex AI, Google’s enterprise AI platform, not the consumer Gemini app or its free API.
Under Google’s Vertex AI terms, the prompts and documents we send for analysis are not used to train or improve Google’s foundation models. Your content is processed to produce your result, and that is all.
Arctis AI likewise does not train, fine-tune, or build any model on your data. There is no shared model that learns from one customer and benefits another. Analysis runs strictly within your organisation’s context, and outputs stay inside your tenant.
To keep analysis reliable we monitor AI quality through Langfuse. Email addresses are automatically redacted from these diagnostics before they are recorded.
Access control and permissions
Access to Arctis AI is governed by enterprise single sign-on and a layered permission model that follows the principle of least privilege.
Sign-in runs through WorkOS, our enterprise identity provider. Every session carries a cryptographically signed token, verified on each request against the provider’s public keys. The organisation a session belongs to is itself a signed claim.
On top of organisation membership, access is granted per project. Administrators assign each member an Editor or Viewer role, and those grants cascade through nested project structures. Members start with no access until it is explicitly granted.
Changes take effect immediately. When an administrator revokes access or changes a role, the new permissions apply on the very next request.
Each organisation is fully isolated
Multi-tenant separation is enforced on every request, at two independent layers.
Encrypted in transit and at rest
Every connection between your browser, our services, and our data stores is secured with TLS. Documents and database contents are encrypted at rest with AES-256 by the underlying managed platforms.
Credentials never live in our source code. Secrets are held in managed secret stores and separated by environment, so staging and production run on entirely different keys.
Secure development and operations
Our development process is designed to keep unsafe changes out of production and to contain what the AI is allowed to do.
Ownership, retention and deletion
You remain the owner of everything you upload. Arctis AI processes it on your behalf, and only for the purpose of serving you.
Deleting a project or document removes it from all views immediately. A recovery window protects you against accidental deletion, and permanent erasure is available on request.
The processes behind these rights (access, deletion and erasure) are documented in our technical and organisational measures and contractually committed in our data-processing agreement.
The services we rely on and why
We work with a small, deliberate set of established providers. Each one has a specific role and sees only what it needs to perform it.
Every provider is a recognised platform with independently audited security certifications. The majority hold both SOC 2 Type II and ISO 27001, and all are GDPR compliant.
