We believe compliance should be verified, not just claimed. That's why we use independent, automated security scanning to continuously assess our infrastructure against regulatory frameworks.
Our compliance posture is assessed by SecurityGuru — an independent, automated platform that scans infrastructure against 500+ security rules and maps findings to regulatory frameworks like GDPR, SOC 2, ISO 27001, and NIS2.
Learn more about SecurityGuruSecurityGuru scans our infrastructure and maps the results to the following regulatory frameworks. Current scores and detailed findings are available on our SecurityGuru profile.
General Data Protection Regulation — EU data protection requirements including data processing agreements, security of processing, breach notification, and privacy by design.
Service Organization Control 2 — Trust service criteria covering security, availability, processing integrity, confidentiality, and privacy.
International standard for information security management systems, covering 93 controls across organizational, people, physical, and technological domains.
Network and Information Security Directive 2 — EU directive on cybersecurity risk management and incident reporting obligations.
SecurityGuru uses a four-step process to assess compliance posture:
Key architectural decisions that underpin our compliance posture:
Prompts are processed in GPU memory (RAM) and discarded after response delivery. No persistent storage of customer data.
Inference and storage run on our own hardware in Solna, Sweden. API and portal traffic is served from EU edge locations only.
Requests are segregated by API key and project on shared inference infrastructure. Dedicated deployments are available under a separate agreement.
All public endpoints are served over TLS, and current clients negotiate TLS 1.3.
SecurityGuru (securityguru.se) — an independent, automated compliance scanning platform. The scanning supports, and does not replace, our own security review; the scan results are generated by SecurityGuru's scanning infrastructure.
SecurityGuru runs scans continuously. Results on their platform reflect the most recent scan data.
No. EU hosting eliminates cross-border transfer issues, but GDPR also requires a Data Processing Agreement (Art. 28), security measures (Art. 32), breach notification procedures (Art. 33), and privacy by design (Art. 25).
Use the contact form below to reach our security team. We're happy to discuss compliance details, share relevant documentation, and answer specific questions about our infrastructure.
Review the scanning results on SecurityGuru or test the zero-retention API yourself.