demi

Security

Your data.
Transparently protected.

demi protects your data: primarily on European infrastructure, with industry-standard encryption, clear contractual commitments, and full disclosure. Our safeguards and every sub-processor are publicly listed.

Anchored in the contract

Commitments you can read for yourself

GDPR data processing: The data processing agreement under Art. 28 GDPR is automatically part of every contract, including publicly available TOMs under Art. 32 GDPR.

EU · EWR · CH
Hosting

EU hosting: Production databases run in data centers in the EU, the EEA, or Switzerland. AI inference runs primarily in EU regions.

No training without opt-in: Identifiable customer data is not used to train AI models without your explicit opt-in. That is the default rule in our DPA.

AES-256
TLS 1.2+

Encryption: Production databases are encrypted at rest with AES-256, transport runs over TLS 1.2+, and backups are stored encrypted and versioned.

Deployment & data residency

EU residency by default, transparent down to the region

Standard

Multi-tenant SaaS in Europe

demi runs as a European-hosted SaaS platform with logical tenant separation: your data is isolated per tenant.

Standard

AI inference in EU regions

Leading AI models run primarily in EU regions. A provider-agnostic model gateway routes every task, with no re-integration on your side.

Clearly defined

Third countries only with safeguards

Where individual services require non-EU regions, EU standard contractual clauses or an adequacy decision secure the transfer.

Which models run in which regions is shown in our model overview

A data foundation you can rely on

EU hosting: Production databases are operated in data centers within the EU, the EEA, or Switzerland.

No training without opt-in: Identifiable customer data is not used for training or fine-tuning AI models without explicit opt-in.

Encryption in transit and at rest: Production databases are encrypted at rest with AES-256; data in transit is protected with TLS 1.2+.

Encrypted backups: Regular encrypted, versioned backups, stored in a second EU region.

Security architecture

Strict access management: Data access follows the least-privilege principle: role-based access control (RBAC) with audit logs, enforced on every request.

Strong authentication: Central login with password policies; multi-factor authentication (TOTP, passkeys) is currently rolling out.

Tenant separation: Logical data separation per tenant: your data stays separated from other customers'.

Logged admin access: Administrative access to personal data is logged. On justified request, we provide a tenant-scoped audit-trail extract.

Compliance & risk management

GDPR-compliant: Data processing under Art. 28 GDPR, automatically part of every contract. Data-subject rights, deletion, and return are clearly defined.

Public TOMs: Our technical and organizational measures under Art. 32 GDPR are publicly available, not an annex behind an NDA.

Transparent sub-processors: The complete list of sub-processors is public and contractually binding. We announce material changes in advance, with objection and special termination rights.

Incident response: A documented incident-response procedure; we report personal data breaches without undue delay, generally within 72 hours.

Regular review: The effectiveness of our measures is reviewed through regular internal security audits and continuously improved.

AI models & inference

Provider-agnostic gateway: A dedicated model gateway routes every task to the right model. Providers underneath are interchangeable, with no re-integration on your side.

EU inference by default: Leading models run primarily in EU regions. Providers, regions, and status are openly listed in the model overview.

Transparent fallback paths: Even failover routes are openly listed in the sub-processor list, including their location. No hidden paths.

Governance & control

Roles and permissions, built in: Fine-grained access control decides on every request who can see and do what. Governance by construction.

Evidence & audits: Typically once a year, we provide suitable evidence of the effectiveness of our measures.

Data export: After the contract ends, you can export your data for at least 30 calendar days (JSON or API).

Deletion & return: Deletion or return of personal data after the contract ends is clearly defined in the contract.