Home  ›  Resources  ›  Data security
🔒
Security & compliance

Data security and sovereignty

For regulated professions, confidentiality is non-negotiable. Here's exactly how we protect your data and your clients' data at every step when you use artificial intelligence — sovereign hosting, GDPR compliance, professional secrecy preserved.

Our guarantees

Six security commitments, built in by design

Compliance isn't bolted on afterwards: it's at the core of every solution we deploy.

Sovereign France / EU hosting

Database hosted in the European Union, sovereign storage in France (OVH). Your data never leaves the European space.

Never used to train models

Your documents and your clients' documents are never used to train public AI models. They are processed for you alone — full stop.

Pseudonymised data

Identifying information is pseudonymised before processing: the AI works on substance, without handling identities in the clear.

GDPR compliance by default

Data minimisation, clear purpose, traceability. GDPR is built into the architecture, not an afterthought.

Strict scope of use

Each agent only answers questions tied to its function and only accesses the data it needs. No drift, no grey area.

Sourced, verifiable answers

Agents draw on your documents (RAG) and cite their sources. Every output is reviewed by a human — no untethered answers.

Professional secrecy: a reinforced framework

For lawyers and notaries, professional secrecy adds an absolute requirement. Our answer is both technical and organisational: pseudonymisation, sovereign hosting, strict scope of use, and above all a non-negotiable principle — AI prepares, drafts, sorts and checks; the professional remains the final guardian of secrecy and validates every output.

The human stays in control, always

No decision is made by AI. Agents are augmented assistants: they absorb repetitive, preparatory work, but validation, advice and decisions stay human. That is the condition for a calm deployment in a demanding profession.

And concretely, on what infrastructure?

Database on Supabase (EU region, Frankfurt), storage on OVH in France, AI APIs (Anthropic's Claude, OpenAI) used in professional mode with a guarantee that data is not reused for training. We don't claim labels we don't hold: we explain precisely what protects your data.

FAQ

Your questions about data security

Where is my data hosted?
Your data is hosted exclusively in the European Union: database in the EU region (Frankfurt) and sovereign storage in France (OVH). It never leaves the European space and remains subject to GDPR.
Is my data used to train the AI?
No. Your documents and your clients' documents are never used to train public AI models. The APIs are used in professional mode, with a contractual guarantee of non-reuse of data for training.
Is the AI usage GDPR-compliant?
Yes. GDPR compliance is built in from design:
  • Data minimisation and pseudonymisation.
  • Sovereign France / EU hosting.
  • Clear purpose and strict scope of use.
  • Traceability of processing.
How is professional secrecy preserved?
Through technical measures (pseudonymisation, sovereign hosting, strict scope of use) and a clear principle: AI prepares and assists, but the professional (lawyer, notary, accountant) remains the final guardian of secrecy and validates every output before any use.
How do you avoid AI errors or "hallucinations"?
Agents rely on RAG (Retrieval-Augmented Generation): they don't "guess", they answer from your documents and verified sources, and cite their sources for instant human verification. Every critical output is reviewed by a human.
Who has access to my data?
Only the processing necessary for the agent's function accesses the relevant data, under strict access control. Data is neither pooled across clients nor shared with unauthorised third parties.

A specific compliance requirement?

Let's talk. We'll frame together what protects your data and your clients' data, before any deployment.

Book a discovery call →