demi

Security

Your data.
Transparently protected.

demi protects your data: primarily on European infrastructure, with industry-standard encryption, clear contractual commitments, and full disclosure. Our safeguards and every sub-processor are publicly listed.

Anchored in the contract

Commitments you can read for yourself

GDPR data processing: The data processing agreement under Art. 28 GDPR is automatically part of every contract, including publicly available TOMs under Art. 32 GDPR.

EU · EWR · CH
Hosting

EU hosting: Production databases run in data centers in the EU, the EEA, or Switzerland. AI inference runs primarily in EU regions.

No training without opt-in: Identifiable customer data is not used to train AI models without your explicit opt-in. That is the default rule in our DPA.

AES-256
TLS 1.2+

Encryption: Production databases are encrypted at rest with AES-256, transport runs over TLS 1.2+, and backups are stored encrypted and versioned.

Permissions by relationship: Every request is checked against your real org structure, not against a static role flag. Roles and relationships (RBAC and ReBAC) decide together who sees what.

Deployment & data residency

EU residency by default, transparent down to the region

Standard

Multi-tenant SaaS in Europe

demi runs as a European-hosted SaaS platform with logical tenant separation: your data is isolated per tenant.

Standard

AI inference in EU regions

Leading AI models run primarily in EU regions. A provider-agnostic model gateway routes every task, with no re-integration on your side.

Clearly defined

Third countries only with safeguards

Where individual services require non-EU regions, EU standard contractual clauses or an adequacy decision secure the transfer.

Which models run in which regions is shown in our model overview

A data foundation you can rely on

EU hosting: Production databases are operated in data centers within the EU, the EEA, or Switzerland.

No training without opt-in: Identifiable customer data is not used for training or fine-tuning AI models without explicit opt-in.

Encryption in transit and at rest: Production databases are encrypted at rest with AES-256; data in transit is protected with TLS 1.2+.

Encrypted backups: Regular encrypted, versioned backups, stored in a second EU region.

Security architecture

Strict access management: Data access follows the least-privilege principle. A dedicated authorization service decides every single request, combining role-based and relationship-based access control (RBAC and ReBAC), with audit logs.

Relationship-based permissions (ReBAC): Who may see what is derived from real relationships, not from a static role flag: tenant, organization, org unit, team, project, and the document tree itself. Permissions inherit along that graph, and targeted exclusions such as private documents or excluded org units override an inherited grant.

Strong authentication: Central login with password policies; multi-factor authentication (TOTP, passkeys) is currently rolling out.

Tenant separation: Logical data separation per tenant: your data stays separated from other customers'.

Logged admin access: Administrative access to personal data is logged. On justified request, we provide a tenant-scoped audit-trail extract.

Compliance & risk management

GDPR-compliant: Data processing under Art. 28 GDPR, automatically part of every contract. Data-subject rights, deletion, and return are clearly defined.

Public TOMs: Our technical and organizational measures under Art. 32 GDPR are publicly available, not an annex behind an NDA.

Transparent sub-processors: The complete list of sub-processors is public and contractually binding. We announce material changes in advance, with objection and special termination rights.

Incident response: A documented incident-response procedure; we report personal data breaches without undue delay, generally within 72 hours.

Regular review: The effectiveness of our measures is reviewed through regular internal security audits and continuously improved.

AI models & inference

Provider-agnostic gateway: A dedicated model gateway routes every task to the right model. Providers underneath are interchangeable, with no re-integration on your side.

EU inference by default: Leading models run primarily in EU regions. Providers, regions, and status are openly listed in the model overview.

Transparent fallback paths: Even failover routes are openly listed in the sub-processor list, including their location. No hidden paths.

Governance & control

Roles and permissions, built in: Fine-grained access control decides on every request who can see and do what, including for AI agents: an agent acting on your behalf never holds more permissions than the person who started it. Governance by construction.

Evidence & audits: Typically once a year, we provide suitable evidence of the effectiveness of our measures.

Data export: After the contract ends, you can export your data for at least 30 calendar days (JSON or API).

Deletion & return: Deletion or return of personal data after the contract ends is clearly defined in the contract.