Security & sovereignty

Enterprise AI with maximum security

ISO 27001-certified, operated by a German company and hosted in Germany & the EU. Your data never leaves the protected legal jurisdiction – and never trains foreign models.

ISO Certified·GDPR Compliant·EU Hosting
Highest standards

Highest standards for encryption, control and certification

ISO 27001:2022
Certified information security management system, audited annually.
SSO, RBAC & Entra ID
Single sign-on, role-based access and MFA – integrated with your identity provider.
No training, no retention
Zero data retention with all model providers – your prompts and documents are neither stored nor used for training.
AES-256 & TLS 1.3
Encrypted at rest (AES-256) and in transit (TLS 1.3).
GDPR-compliant
Processing under Art. 28 GDPR, data processing agreement included.
Hosted in Germany & the EU
Platform and database on Hetzner in German data centers – ISO 27001 & C5 attested.
Hosting & infrastructure

Platform and database – in Germany, on Hetzner

No overseas cloud: meinGPT runs its platform and database on dedicated Hetzner infrastructure in German data centers (Falkenstein, Nuremberg) – ISO 27001-certified and C5-attested. meinGPT's own C5 is in progress.

🇩🇪 Germany
Falkenstein
Nürnberg
Platform
Database
ISO 27001C5
Data ownership

Your data belongs to you. Period.

The key difference from public AI models? We don't learn from you. meinGPT acts as a secure proxy layer between your company and the LLM providers. We guarantee – contractually and technically – that your inputs (prompts) and uploaded documents are never used to train the AI models. What happens in your company stays in your company.

LLM provider
Your request
0 bytes retained
Zero data retention · no training
In detail

The security measures we implement in detail

Platform & infrastructure

Learn more
Dedicated infrastructure

We run our platform on dedicated servers in highly available Kubernetes clusters with strictly separated environments for the core platform, AI applications and sandboxes. (Managed Kubernetes, encrypted control plane, separated clusters)

Isolated AI execution

All AI-generated content is processed in specially secured AI sandboxes that are isolated from one another by virtual machines on top of containerization. (Container and VM isolation, no direct access to platform data)

Secure supply chain

All container images are automatically scanned for vulnerabilities before deployment and rescanned regularly to minimize software supply-chain risk. (Image scanning, runtime checks, vetted images)

Data, access & tenant protection

Learn more
Tenant encryption

Customer data is stored encrypted and additionally secured per tenant, so an incident always stays contained to a single tenant. (Combination of platform key and tenant key – documents, chats, knowledge bases)

Strict access control

Access to systems and data is role-based and secured by multi-factor authentication; production infrastructure is reserved for a very small, defined group of people. (RBAC, MFA, restricted support roles)

Controlled AI data flows

Requests to AI models are technically anonymized so providers cannot draw conclusions about individual tenants, with full transparency over the providers used. (EU-based providers, configurable model selection)

Operations, monitoring & evidence

Learn more
Monitoring & anomaly detection

Security-relevant activity is centrally logged and continuously monitored to detect anomalies early and respond in a targeted way. (Audit logs, AI-based anomaly detection)

Testing & assurance

The platform is regularly examined for weaknesses through external grey-box penetration tests and internal security reviews. (Semi-annual pentests, continuous scans)

Compliance & transparency

Our security organization aligns with established standards and is transparently documented for customers. (ISO 27001-based ISMS, EU data centers)

Advanced security

Need even more security?

By default, meinGPT is already secured at enterprise level. If you need even more sovereignty, you can unlock three further tiers – from the Privacy Proxy and DataVault to your own models hosted in Germany.

Privacy Proxy

Sensitive data never reaches the model in the first place

The meinGPT Privacy Proxy detects and anonymizes personal and sensitive data before a request leaves the platform. The model provider only ever sees pseudonymized content – the mapping back to clear text stays exclusively in your environment.

Your request
Max Mustermannmax@firma.de·Kundennr. 4711
meinGPT Privacy Proxy
LLM provider sees
[NAME][E-MAIL]·[ID]
Re-identification only on your side
DataVault

Make your company knowledge usable – without giving it away

DataVault makes internal documents and knowledge sources usable for AI without handing them over. The connection is outbound-only and, on request, fully on-premises – your knowledge never leaves your infrastructure.

Hybrid RAG
Semantic vector search combined with keyword search (BM25) for precise answers on your data.
Outbound-only connection
Synchronization only initiates outbound connections – no inbound ports into your network.
On-premises option
On request, DataVault runs entirely within your own infrastructure.
Sovereignty levels

You decide how sovereign it needs to be

From EU-hosted models to fully self-hosted LLMs on German hardware – meinGPT scales with your data-sovereignty requirements.

L1
L2
L3
L4
EU models
Processing: EU data center
L1
EU models
Models hosted exclusively in the EU (e.g. Mistral EU).
L2
EU hyperscalers
Azure EU & Google Vertex EU – processed within the EU.
L3
Global top models
Leading US models under EU standard contractual clauses / Data Privacy Framework.
L4
Maximum sovereignty
PII filtering + Privacy Proxy and your own LLMs on Hetzner GPUs in Germany.
Transparency

Full transparency over the models in use

You can always see which models are processed where – and choose yourself which ones you allow. All providers operate with zero data retention.

MistralProcessing: EUZero retention
Azure OpenAIProcessing: EUZero retention
Google Vertex (Gemini)Processing: EU / globalZero retention
Anthropic ClaudeProcessing: EU / US (DPF)Zero retention
PerplexityProcessing: US (DPF)Zero retention

Note: some leading global models are processed outside the EU (under DPF/SCC) – this is labeled per model and can be disabled for your tenant.

Trust Center

Trust is good, control is better

The Trust Center

Our Trust Center gives you insight into our security architecture: every implemented security control, certificates and subprocessors – synced straight from our compliance system.

Open Trust Center
Deep dive for admins

In our documentation, IT security officers find all the details on encryption (AES-256), deletion periods and architecture diagrams.

Read the technical docs
For IT, data protection & procurement

The documents your buying process needs

Penetration-test report and our internal security policies for vendor audits, GDPR reviews and security questionnaires – unlocked instantly with your business email. You'll find the ISO 27001 certificate further up on this page.

Confidential documents. We'll also email you the download link – so you can forward it to your teams.

  • Penetration-test report (SySS, 2025)Email required
    For IT security & vendor audits
  • ISMS policy (POL-02)Email required
    For data protection & compliance
  • Incident-management policy (POL-17)Email required
    For security questionnaires & procurement
What's next

We're far from done

We continually pursue higher security standards to meet the requirements of ever-larger enterprises.

2025
ISO 27001
Certified ISMS – active since 2025.
2026
ISO 42001
AI management system for responsible AI.
Next
SOC 2 Type II
Extended assurance for international customers.
FAQ

Frequently asked security questions

Yes. meinGPT supports SSO via common identity providers including Microsoft Entra ID, plus role-based access control (RBAC) and multi-factor authentication.

Go deeper

ISO Certified
GDPR Compliant
EU Hosting

Start with AI in your company

Together we find the right use cases, connect your systems, and bring AI into daily work—aligned with your business.