Security
Your data.
Transparently protected.
demi protects your data: primarily on European infrastructure, with industry-standard encryption, clear contractual commitments, and full disclosure. Our safeguards and every sub-processor are publicly listed.
Anchored in the contract
Commitments you can read for yourself
GDPR data processing: The data processing agreement under Art. 28 GDPR is automatically part of every contract, including publicly available TOMs under Art. 32 GDPR.
EU hosting: Production databases run in data centers in the EU, the EEA, or Switzerland. AI inference runs primarily in EU regions.
No training without opt-in: Identifiable customer data is not used to train AI models without your explicit opt-in. That is the default rule in our DPA.
Encryption: Production databases are encrypted at rest with AES-256, transport runs over TLS 1.2+, and backups are stored encrypted and versioned.
Permissions by relationship: Every request is checked against your real org structure, not against a static role flag. Roles and relationships (RBAC and ReBAC) decide together who sees what.
Deployment & data residency
EU residency by default, transparent down to the region
Multi-tenant SaaS in Europe
demi runs as a European-hosted SaaS platform with logical tenant separation: your data is isolated per tenant.
AI inference in EU regions
Leading AI models run primarily in EU regions. A provider-agnostic model gateway routes every task, with no re-integration on your side.
Third countries only with safeguards
Where individual services require non-EU regions, EU standard contractual clauses or an adequacy decision secure the transfer.
Which models run in which regions is shown in our model overview
A data foundation you can rely on
EU hosting: Production databases are operated in data centers within the EU, the EEA, or Switzerland.
No training without opt-in: Identifiable customer data is not used for training or fine-tuning AI models without explicit opt-in.
Encryption in transit and at rest: Production databases are encrypted at rest with AES-256; data in transit is protected with TLS 1.2+.
Encrypted backups: Regular encrypted, versioned backups, stored in a second EU region.
Security architecture
Strict access management: Data access follows the least-privilege principle. A dedicated authorization service decides every single request, combining role-based and relationship-based access control (RBAC and ReBAC), with audit logs.
Relationship-based permissions (ReBAC): Who may see what is derived from real relationships, not from a static role flag: tenant, organization, org unit, team, project, and the document tree itself. Permissions inherit along that graph, and targeted exclusions such as private documents or excluded org units override an inherited grant.
Strong authentication: Central login with password policies; multi-factor authentication (TOTP, passkeys) is currently rolling out.
Tenant separation: Logical data separation per tenant: your data stays separated from other customers'.
Logged admin access: Administrative access to personal data is logged. On justified request, we provide a tenant-scoped audit-trail extract.
Compliance & risk management
GDPR-compliant: Data processing under Art. 28 GDPR, automatically part of every contract. Data-subject rights, deletion, and return are clearly defined.
Public TOMs: Our technical and organizational measures under Art. 32 GDPR are publicly available, not an annex behind an NDA.
Transparent sub-processors: The complete list of sub-processors is public and contractually binding. We announce material changes in advance, with objection and special termination rights.
Incident response: A documented incident-response procedure; we report personal data breaches without undue delay, generally within 72 hours.
Regular review: The effectiveness of our measures is reviewed through regular internal security audits and continuously improved.
AI models & inference
Provider-agnostic gateway: A dedicated model gateway routes every task to the right model. Providers underneath are interchangeable, with no re-integration on your side.
EU inference by default: Leading models run primarily in EU regions. Providers, regions, and status are openly listed in the model overview.
Transparent fallback paths: Even failover routes are openly listed in the sub-processor list, including their location. No hidden paths.
Governance & control
Roles and permissions, built in: Fine-grained access control decides on every request who can see and do what, including for AI agents: an agent acting on your behalf never holds more permissions than the person who started it. Governance by construction.
Evidence & audits: Typically once a year, we provide suitable evidence of the effectiveness of our measures.
Data export: After the contract ends, you can export your data for at least 30 calendar days (JSON or API).
Deletion & return: Deletion or return of personal data after the contract ends is clearly defined in the contract.
