Skip to content
souveraen.ai
Security and data protection

Security and data protection in every operating mode.

souveraen.ai checks access rights on every request, logs retrievals and actions, and only changes data in your systems after an approval. Your data is not used to train models.

At a glance
Location
Local or hosted in Germany
Model training
Not with your data
External models
In EU and ZDR tenants
Access check
On every request
Changes in your systems
Only after approval
Audit log
Retrievals, approvals, actions

Applies to On Demand, Private Spark and Air-Gap Enterprise.

Operating modes

Where your data is processed.

You choose the operating mode. Access checks, logging and approvals work the same way in all three.

On Demand

Hosted in Germany

souveraen.ai runs in data centres in Germany. Every customer has a separate tenant. We sign a GDPR data processing agreement with you.

Prices of the operating modes
Location
Data centres in Germany
Network
Access over the internet
Models
Open-weight models in hosting
External models
Vendors' EU and ZDR tenants
Hardware
No hardware of your own

Controls

What the platform enforces on every request.

These rules are implemented technically. They do not depend on prompts or on settings of individual users.

Tenant isolation

Every customer has a separate tenant. Documents, search index and logs are kept apart from other customers.

Access check

Every request checks which workspaces the person may see. Content without permission does not appear in the answer.

„What terms do we have with Müller?“

L. Berger · Purchasing

Framework contract, price list

Sales internal

J. Weber · Sales

Framework contract, sales internal

Purchasing price list

No training on your data

Models run in fixed versions and are not further trained on your content.

External models in EU and ZDR tenants

In On Demand, external models are processed in the vendors' EU and zero-data-retention (ZDR) tenants. On Private Spark they are optional; on Air-Gap Enterprise they are not connected.

External modelsEU/ZDR

Audit log

Retrievals, approvals and executed actions are logged with person and time.

  • 09:14L. BergerRequest, 3 sources
  • 09:16Purchasing agentTicket draft created
  • 09:21M. KrauseApproval given

Sources

Every answer names its sources. If sources are missing or contradict each other, the answer says so.

Agents and tools

Changes in your systems only after approval.

Every tool an agent may use has a fixed risk class. It is set when the tool is registered, not by the AI during a conversation.

  • ReadSearch a ticket, open a wiki pageRuns without asking and is logged.No approval
  • WriteCreate a ticket, change a recordApproval of the exact content required.Needs approval
  • ExternalSend a message to third partiesApproval required.Needs approval
  • ComputeAnalyse a spreadsheetRuns in an isolated environment without network access.No approval
Tools and risk classes in detail
Approval inbox
Waiting for your approval
Quality assurance agentjira.create_issue · Write
Project
QA
Title
Complaint batch 24-117
Priority
High
FAQ

Questions from IT and data protection.

Short answers. We are happy to go through your requirements in a call.

Your own list of requirements?

Send us the requirements of your IT security and data protection. We show what the platform implements technically and what stays organisational on your side.

Book a call

Not with Air-Gap Enterprise. With Private Spark, the data stays on the local installation unless you add external models. With On Demand, the data sits in your tenant in data centres in Germany. If you use an external model, the request is processed in the vendors' EU and zero-data-retention (ZDR) tenants.

For IT and data protection

Review your requirements with us.

Send us your list of requirements. We go through it with you point by point before you decide on an operating mode.

  1. Send your requirements1
  2. Call with IT and data protection2
  3. Choose the operating mode3