Transparency instead of promises.

This is where we document how we handle your data, AI and security – and what is already in place today.

Our binding principles

No training on your data

Confidential customer data is not used to train AI models without a separate, explicit agreement.

Human oversight

Professionally relevant AI results are reviewed by people. AI suggestion and human approval are clearly separated.

Tenant separation

Data of different customers and projects is processed strictly separately.

Data minimisation

We collect only what we need and delete in a controlled way.

Documented AI providers

AI services used and processing locations will be published before the platform goes live.

No unproven claims

We only mention certifications and audits once they actually exist.

Already in place today

These measures apply to the public website and its request forms.

  • Encrypted transport (HTTPS/TLS)
  • Hosting with IONOS in the EU
  • Locally served fonts – no external font services
  • Analytics only after consent (Google Consent Mode v2)
  • No form contents sent to analytics
  • Server-side validation, rate limiting and spam protection
  • Automatic deletion of stored requests after the retention period

Platform security architecture

Security by design and privacy by design apply to the AI workspace. These measures are part of the architecture before any customer data is processed.

  • Secure authentication and role-based permissions
  • Encryption of sensitive data and documents
  • Audit logs for professionally relevant events
  • Protection against prompt injection and unauthorised data access
  • Data processing agreements where required
  • Backup, recovery and defined deletion periods

Security questions from your procurement or IT?

We answer questionnaires and provide documentation as soon as it is available.