Transparency instead of promises.
This is where we document how we handle your data, AI and security – and what is already in place today.
Our binding principles
No training on your data
Confidential customer data is not used to train AI models without a separate, explicit agreement.
Human oversight
Professionally relevant AI results are reviewed by people. AI suggestion and human approval are clearly separated.
Tenant separation
Data of different customers and projects is processed strictly separately.
Data minimisation
We collect only what we need and delete in a controlled way.
Documented AI providers
AI services used and processing locations will be published before the platform goes live.
No unproven claims
We only mention certifications and audits once they actually exist.
Already in place today
These measures apply to the public website and its request forms.
- Encrypted transport (HTTPS/TLS)
- Hosting with IONOS in the EU
- Locally served fonts – no external font services
- Analytics only after consent (Google Consent Mode v2)
- No form contents sent to analytics
- Server-side validation, rate limiting and spam protection
- Automatic deletion of stored requests after the retention period
Platform security architecture
Security by design and privacy by design apply to the AI workspace. These measures are part of the architecture before any customer data is processed.
- Secure authentication and role-based permissions
- Encryption of sensitive data and documents
- Audit logs for professionally relevant events
- Protection against prompt injection and unauthorised data access
- Data processing agreements where required
- Backup, recovery and defined deletion periods
Security questions from your procurement or IT?
We answer questionnaires and provide documentation as soon as it is available.