Trust Center · security, privacy and DORA documentation

We help you handle compliance. Here is how we handle our own.

Audomate analyses your contracts, policies and evidence. We run on 100% EU infrastructure with on-premise LLM options, so there is no data transfer outside the EU and no Schrems II exposure — a claim US-based platforms cannot make. Before you hand us your first document, you have every right to know where exactly we process data, how the AI uses it, what we keep and how we respond to failures. You will find the answers here — along with the certifications we do not hold yet.

100% EU infrastructure for processing, storage and AIZero Schrems II risk no data transfer outside the EUNo AI training on customer data — by us or by the model providerOn-premise available including an on-premise LLM stack
01 Infrastructure and data residency

Your data stays in the EEA. So do the backups.

The platform runs in Google Cloud regions inside the EU, and its interface is served from edge servers within the European Economic Area (EEA). No request leaves the EEA — that covers compute, storage, AI analysis and disaster recovery. Because nothing is transferred to a third country, running Audomate needs no standard contractual clauses and carries no Schrems II exposure.

Processing and storage regions
RegionLocationPurposeStatus
europe-west1BelgiumPrimary compute and databaseActive
europe-west3Frankfurt, GermanyDisaster recoveryActive
europe-west4NetherlandsRedundant object storage copiesActive
Outside the EEAAnyProcessing or storage of dataNot used
99.9–99.95%
Availability, depending on the plan
< 30 s
Automatic failover to the standby database
1–4 h
Recovery point objective (RPO)
4–8 h
Recovery time objective (RTO)
02 Data processing and storage

You keep control of your documents and of deleting them.

Customer documents are encrypted in transit (TLS 1.3, with TLS 1.2 as the minimum version) and at rest (AES-256, customer-managed keys in Cloud KMS, rotated every 90 days). Two independent layers separate one organisation's data from another's: role-based permissions in the application (RBAC) and row-level access control in the database. That design makes access to another organisation's data impossible.

Data categories and retention periods
CategoryWhere it is processedRetention
Uploaded documents (PDF/DOCX)Object storage and vector index in the EEAUntil you ask us to delete them, after which they are permanently erased
Personal data inside documentsRelational database in the EEANo longer than necessary — Art. 5 GDPR
AI session contextWorking memory only, for the duration of the sessionDiscarded when the session ends; never written to durable storage
Compliance reportsData store in the EEA with version historyIn line with your organisation's policy
Audit trailA log with a cryptographic hash chain that makes tampering detectableAt least one year (Art. 25 DORA), or longer by contract
  • A single deletion process covers the vector index, the relational database and object storage.
  • Backups allow point-in-time recovery. We keep them in two regions, both inside the EEA.
  • Every user action, AI assessment and human override of an assessment goes into an append-only log. A cryptographic hash chain makes any change to its history detectable.
03 AI usage rules and model governance

The final decision belongs to a person.

Audomate uses retrieval-augmented generation (RAG) inside a verification framework: every generated finding and document is grounded in the actual regulation and your actual evidence, carries source references and a confidence indicator, and anything the model cannot ground is marked for review rather than stated as fact. The person responsible for compliance reviews, edits or overrides every assessment. We record who decided, when and why. The AI proposes; your team decides.

  • The LLMs run in enterprise services inside the EEA, under a contractual zero-retention rule. The model provider does not store prompts or responses. They are never used to train models — not by us and not by the provider.
  • Each organisation's audit session is fully isolated. Its context stays in working memory only until the session ends.
  • Before any content reaches the model, an input gateway detects prompt injection attempts and sanitises the input.
  • Every organisation has a token usage limit and receives alerts on consumption. That keeps the scale of processing under control.
  • Organisations that need full independence from external model providers can deploy their own way: an on-premise LLM stack, a portable hardware box or a white-label instance, alongside the standard EU SaaS.
04 Platform and organisational security

Controls at every layer of the system.

  • Network — a WAF in front of the API protects against the OWASP Top 10 and limits DDoS attacks. Internal services communicate over mTLS, and the data layer runs on a private network with no public IP addresses.
  • Sign-in — SSO via SAML 2.0 or OIDC with your organisation's identity provider, such as Microsoft Entra ID. Multi-factor authentication (MFA) is mandatory. Access tokens are valid for 15 minutes and refresh tokens are rotated.
  • Permissions — role-based access in the application is additionally enforced at the database row level. Credentials are held in a managed secret store, with access logging and 90-day rotation.
  • The team — the experts building the platform advise the European Commission on digital identity wallets, sit on the CEN and PKN standardisation committees and advise the Polish Bank Association on AML, eIDAS and PSD.
  • Software development — systematic code review, dependency scanning and testing before every release of a new version of the application
05 Sub-processors

You know who processes the data. We announce changes in advance.

Below are the providers that support the Audomate platform. All of them process data in EEA regions only. We give 30 days' notice before adding or changing a sub-processor. The period for objecting is set out in the data processing agreement. The full sub-processor list is pending publication.

EntityServicesRegionData accessed
Google Cloud (Google Ireland Ltd)Compute, storage, database and key managementEEA (BE/DE/NL)Encrypted customer material
Microsoft Azure OpenAI ServiceLLM hosting in the EEA, with no data retentionEEAPrompt content, for the duration of processing only
Okta (Auth0), EU regionIdentity management and single sign-onEEANames, email addresses and authentication logs
06 Personal data protection — GDPR

We process data under a contract and keep its scope narrow.

  • For customer documents, your organisation is the controller and DeepTech sp. z o.o. is the processor. We sign a data processing agreement for every deployment, with annexes describing the technical and organisational measures and the sub-processors.
  • Personal data is not transferred outside the EEA. Running the platform therefore requires no standard contractual clauses (SCCs) and no reliance on adequacy decisions.
  • We inform affected customers of personal data breaches without undue delay, within 24 hours at the latest. Notification to the supervisory authority follows within 72 hours where Art. 33 GDPR requires it.
  • The platform supports data subject rights: access, rectification, erasure and restriction of processing. That includes permanent deletion across every storage layer.
  • We maintain an internal record of processing activities (RoPA). We make it available for review once an NDA is signed.
07 For customers in scope of DORA

The documentation you need to assess us as an ICT vendor.

If your organisation is subject to DORA, you will list us in your register of information as an ICT third-party service provider. We have prepared the data and documents needed to assess us. The full pack is available on request — it contains the information below in a form ready to use in the register.

Vendor data for the register of information
FieldValue
Full nameDeepTech sp. z o.o.
Registered addressul. Chmielna 132/134, 00-805 Warsaw, Poland
IdentifiersKRS 0001127965 · NIP 5273130678 · REGON 529687065
LEIWe do not hold one. In the register of information you can identify DeepTech through the EUID derived from KRS number 0001127965. The European supervisory authorities' implementing technical standards (ITS) allow this where a provider has no LEI.
Type of serviceSaaS software supporting ICT vendor management, audits and compliance monitoring
Data locationseurope-west1 (BE) — primary · europe-west3 (DE) — disaster recovery · europe-west4 (NL) — storage
Subcontracting chainSee section 05 for the list of sub-processors
  • Incident notification — we inform your named contacts of critical incidents affecting your organisation within 30 minutes on the Enterprise plan, or 24 hours on the Standard and Pro plans. A written report follows within 24 hours.
  • Audit and access rights — the contract gives you and the competent supervisory authorities audit, information and access rights in line with Art. 30(3) DORA.
  • Termination — we provide a full data export in open formats (PDF, DOCX, CSV, JSON), confirmed permanent deletion, and transition assistance for 30 days after the contract ends.
  • Business continuity — infrastructure in two regions, automatic failover and documented RTO/RPO per plan (section 01). A summary of the continuity arrangements is in the document library.

Request the DORA documentation

08 Certifications and plans

Our infrastructure's certifications, and DeepTech's own certification plans.

We distinguish our infrastructure provider's certifications from our own organisation's. The infrastructure layer relies on Google Cloud's certifications. Preparations for DeepTech's own certification are under way. When the report is available, we will publish it here.

Certification or documentEntityStatus
ISO 27001, SOC 2, CSA STAR — hosting layerGoogle CloudCertified infrastructure — we rely on the provider's controls
Data processing agreement with a description of technical and organisational measuresDeepTechSigned for every deployment
ISO 27001 — the DeepTech organisationDeepTechIn preparation — targeted for H1 2027
Independent penetration testDeepTechPlanned for Q1 2027; a summary will be published
09 Document library

The documents you need in order to verify Audomate.

Documents marked “In preparation” are drafts. The information highlighted in them is awaiting internal confirmation. The materials below are pending publication; deployment documentation is available on request.

Pending publication

Privacy policy

What data we collect on the website and the platform, why, and how long we keep it. Includes our cookie rules.

The document is not available yet
In preparation

Security overview

A public summary of our network, sign-in, encryption, monitoring and incident response controls.

The document is not available yet
In preparation

Sub-processor list

The list of sub-processors referenced in the data processing agreement, and how we announce changes.

The document is not available yet
In preparation

AI usage and data processing rules

The models and where they run, the zero-retention rules, human oversight and our approach to the AI Act.

The document is not available yet
In preparation

Incident response rules

Incident severity levels, escalation rules and notification deadlines for customers and supervisory authorities.

The document is not available yet
In preparation

Data retention and deletion policy

Data categories, retention periods and how permanent deletion works.

The document is not available yet
In preparation

Business continuity and disaster recovery

Two-region infrastructure, failover, RTO/RPO and how the service behaves under degraded availability.

The document is not available yet
Legal review

Audomate terms of service

The agreement setting out the binding terms for using the Audomate platform.

Awaiting legal review
On request

Data processing agreement

The processing terms, with annexes describing the security controls and the sub-processors. Signed for every deployment.

Request the document
On request

DORA vendor documentation pack

Register of information data, incident notification rules, audit rights and termination terms.

Request the documentation
Under NDA

Record of processing activities and internal policies

The record of processing activities (RoPA) and the full internal security policy documentation.

Request access
10 Assessing Audomate as a vendor

Reviewing us as a vendor? Send us your questionnaire.

We will complete it in your own format. We will say which controls are already in place and which are still planned. Security questions and vulnerability reports go to security@deeptech.pl.

Write to the team

Content last reviewed: 22-09-2026