Skip to content
Security

Your data stays in Europe.

KoAssist runs entirely on European infrastructure: hosting in German data centres, language processing in EU data centres, no training on your data.

Hosted in Germany

ISO 27001 certified data centres, no transfers to third countries.

No training on your data

Contractually guaranteed and technically prevented.

GDPR and DPA

DPA under Art. 28 as standard, TOMs attached.

Deletion within 48 h

On written request, with a deletion log.

Data flow

Where your data lives.

  1. 01YOUR PREMISES

    Your systems

    Standards, specs, project documents live in your systems: SharePoint, PLM, network drives. They remain the authoritative source.

    • No system migration
    • Connected via open interfaces
  2. 02DE

    German servers

    A synced copy of your documents, the index and the search logic live on ISO 27001-certified servers in Germany.

    • Encrypted in transit
    • Encrypted at rest
    • Anonymized before model call
  3. 03EU

    Language model in the EU

    Language processing exclusively on EU infrastructure. Where models from US providers are used, they run in EU data centres.

    • No training on your data
    • Contractually guaranteed

Return path: Answer with source reference (file, page) returned to the query, without storage at the model provider.

What we don't do

Five things KoAssist deliberately does not do.

  • No training of generic foundation models on your engineering data: contractually guaranteed, technically isolated.
  • No shadow IT risk through private ChatGPT accounts: engineers get an approved, documented channel instead of secretly uploading specs.
  • No automatic data outflow to other systems. Integrations are explicit per source and per knowledge space.
  • No hidden sub-processors. Complete list available, changes announced 30 days in advance.
  • No indefinite data retention. Deletion within 48 hours on request, documented.
FAQ

Common questions from IT and data privacy.

Which sub-processors are used?

One hosting provider with data centres in Germany and one language model provider on EU infrastructure, both ISO 27001-certified. Complete list with roles, locations and specific provider names is part of the security document, available on request.

What does the data processing agreement look like?

Standardized GDPR-compliant DPA per Art. 28 with all typical clauses, TOMs as annex, technical measures documented. Sent on request.

Can we export and delete all data?

Yes. Everything held on our side is deleted: the copies of your documents, the index and the embeddings, within 48 hours on written request and with a deletion protocol. Your source systems are unaffected. Conversation history is exportable per user.

Which model providers are used and where do they run?

Language models that run exclusively on EU infrastructure, even where the provider is based in the US. Specific provider details are part of the security document. On request we discuss alternative model setups.

Who has access to customer data?

Access to production customer environments is restricted to a small, individually documented group of people at Soneo AI, with audit logs. No third-party access without explicit consent.

Security questions?

Write to us directly. We respond within one business day. info@soneo.ai

Send an email