We help you handle compliance. Here is how we handle our own.
Audomate analyses your contracts, policies and evidence. We run on 100% EU infrastructure with on-premise LLM options, so there is no data transfer outside the EU and no Schrems II exposure — a claim US-based platforms cannot make. Before you hand us your first document, you have every right to know where exactly we process data, how the AI uses it, what we keep and how we respond to failures. You will find the answers here — along with the certifications we do not hold yet.
Your data stays in the EEA. So do the backups.
The platform runs in Google Cloud regions inside the EU, and its interface is served from edge servers within the European Economic Area (EEA). No request leaves the EEA — that covers compute, storage, AI analysis and disaster recovery. Because nothing is transferred to a third country, running Audomate needs no standard contractual clauses and carries no Schrems II exposure.
| Region | Location | Purpose | Status |
|---|---|---|---|
europe-west1 | Belgium | Primary compute and database | Active |
europe-west3 | Frankfurt, Germany | Disaster recovery | Active |
europe-west4 | Netherlands | Redundant object storage copies | Active |
| Outside the EEA | Any | Processing or storage of data | Not used |
You keep control of your documents and of deleting them.
Customer documents are encrypted in transit (TLS 1.3, with TLS 1.2 as the minimum version) and at rest (AES-256, customer-managed keys in Cloud KMS, rotated every 90 days). Two independent layers separate one organisation's data from another's: role-based permissions in the application (RBAC) and row-level access control in the database. That design makes access to another organisation's data impossible.
| Category | Where it is processed | Retention |
|---|---|---|
| Uploaded documents (PDF/DOCX) | Object storage and vector index in the EEA | Until you ask us to delete them, after which they are permanently erased |
| Personal data inside documents | Relational database in the EEA | No longer than necessary — Art. 5 GDPR |
| AI session context | Working memory only, for the duration of the session | Discarded when the session ends; never written to durable storage |
| Compliance reports | Data store in the EEA with version history | In line with your organisation's policy |
| Audit trail | A log with a cryptographic hash chain that makes tampering detectable | At least one year (Art. 25 DORA), or longer by contract |
- A single deletion process covers the vector index, the relational database and object storage.
- Backups allow point-in-time recovery. We keep them in two regions, both inside the EEA.
- Every user action, AI assessment and human override of an assessment goes into an append-only log. A cryptographic hash chain makes any change to its history detectable.
The final decision belongs to a person.
Audomate uses retrieval-augmented generation (RAG) inside a verification framework: every generated finding and document is grounded in the actual regulation and your actual evidence, carries source references and a confidence indicator, and anything the model cannot ground is marked for review rather than stated as fact. The person responsible for compliance reviews, edits or overrides every assessment. We record who decided, when and why. The AI proposes; your team decides.
- The LLMs run in enterprise services inside the EEA, under a contractual zero-retention rule. The model provider does not store prompts or responses. They are never used to train models — not by us and not by the provider.
- Each organisation's audit session is fully isolated. Its context stays in working memory only until the session ends.
- Before any content reaches the model, an input gateway detects prompt injection attempts and sanitises the input.
- Every organisation has a token usage limit and receives alerts on consumption. That keeps the scale of processing under control.
- Organisations that need full independence from external model providers can deploy their own way: an on-premise LLM stack, a portable hardware box or a white-label instance, alongside the standard EU SaaS.
Controls at every layer of the system.
- Network — a WAF in front of the API protects against the OWASP Top 10 and limits DDoS attacks. Internal services communicate over mTLS, and the data layer runs on a private network with no public IP addresses.
- Sign-in — SSO via SAML 2.0 or OIDC with your organisation's identity provider, such as Microsoft Entra ID. Multi-factor authentication (MFA) is mandatory. Access tokens are valid for 15 minutes and refresh tokens are rotated.
- Permissions — role-based access in the application is additionally enforced at the database row level. Credentials are held in a managed secret store, with access logging and 90-day rotation.
- The team — the experts building the platform advise the European Commission on digital identity wallets, sit on the CEN and PKN standardisation committees and advise the Polish Bank Association on AML, eIDAS and PSD.
- Software development — systematic code review, dependency scanning and testing before every release of a new version of the application
You know who processes the data. We announce changes in advance.
Below are the providers that support the Audomate platform. All of them process data in EEA regions only. We give 30 days' notice before adding or changing a sub-processor. The period for objecting is set out in the data processing agreement. The full sub-processor list is pending publication.
| Entity | Services | Region | Data accessed |
|---|---|---|---|
| Google Cloud (Google Ireland Ltd) | Compute, storage, database and key management | EEA (BE/DE/NL) | Encrypted customer material |
| Microsoft Azure OpenAI Service | LLM hosting in the EEA, with no data retention | EEA | Prompt content, for the duration of processing only |
| Okta (Auth0), EU region | Identity management and single sign-on | EEA | Names, email addresses and authentication logs |
We process data under a contract and keep its scope narrow.
- For customer documents, your organisation is the controller and DeepTech sp. z o.o. is the processor. We sign a data processing agreement for every deployment, with annexes describing the technical and organisational measures and the sub-processors.
- Personal data is not transferred outside the EEA. Running the platform therefore requires no standard contractual clauses (SCCs) and no reliance on adequacy decisions.
- We inform affected customers of personal data breaches without undue delay, within 24 hours at the latest. Notification to the supervisory authority follows within 72 hours where Art. 33 GDPR requires it.
- The platform supports data subject rights: access, rectification, erasure and restriction of processing. That includes permanent deletion across every storage layer.
- We maintain an internal record of processing activities (RoPA). We make it available for review once an NDA is signed.
The documentation you need to assess us as an ICT vendor.
If your organisation is subject to DORA, you will list us in your register of information as an ICT third-party service provider. We have prepared the data and documents needed to assess us. The full pack is available on request — it contains the information below in a form ready to use in the register.
| Field | Value |
|---|---|
| Full name | DeepTech sp. z o.o. |
| Registered address | ul. Chmielna 132/134, 00-805 Warsaw, Poland |
| Identifiers | KRS 0001127965 · NIP 5273130678 · REGON 529687065 |
| LEI | We do not hold one. In the register of information you can identify DeepTech through the EUID derived from KRS number 0001127965. The European supervisory authorities' implementing technical standards (ITS) allow this where a provider has no LEI. |
| Type of service | SaaS software supporting ICT vendor management, audits and compliance monitoring |
| Data locations | europe-west1 (BE) — primary · europe-west3 (DE) — disaster recovery · europe-west4 (NL) — storage |
| Subcontracting chain | See section 05 for the list of sub-processors |
- Incident notification — we inform your named contacts of critical incidents affecting your organisation within 30 minutes on the Enterprise plan, or 24 hours on the Standard and Pro plans. A written report follows within 24 hours.
- Audit and access rights — the contract gives you and the competent supervisory authorities audit, information and access rights in line with Art. 30(3) DORA.
- Termination — we provide a full data export in open formats (PDF, DOCX, CSV, JSON), confirmed permanent deletion, and transition assistance for 30 days after the contract ends.
- Business continuity — infrastructure in two regions, automatic failover and documented RTO/RPO per plan (section 01). A summary of the continuity arrangements is in the document library.
Our infrastructure's certifications, and DeepTech's own certification plans.
We distinguish our infrastructure provider's certifications from our own organisation's. The infrastructure layer relies on Google Cloud's certifications. Preparations for DeepTech's own certification are under way. When the report is available, we will publish it here.
| Certification or document | Entity | Status |
|---|---|---|
| ISO 27001, SOC 2, CSA STAR — hosting layer | Google Cloud | Certified infrastructure — we rely on the provider's controls |
| Data processing agreement with a description of technical and organisational measures | DeepTech | Signed for every deployment |
| ISO 27001 — the DeepTech organisation | DeepTech | In preparation — targeted for H1 2027 |
| Independent penetration test | DeepTech | Planned for Q1 2027; a summary will be published |
The documents you need in order to verify Audomate.
Documents marked “In preparation” are drafts. The information highlighted in them is awaiting internal confirmation. The materials below are pending publication; deployment documentation is available on request.
Privacy policy
What data we collect on the website and the platform, why, and how long we keep it. Includes our cookie rules.
The document is not available yetSecurity overview
A public summary of our network, sign-in, encryption, monitoring and incident response controls.
The document is not available yetSub-processor list
The list of sub-processors referenced in the data processing agreement, and how we announce changes.
The document is not available yetAI usage and data processing rules
The models and where they run, the zero-retention rules, human oversight and our approach to the AI Act.
The document is not available yetIncident response rules
Incident severity levels, escalation rules and notification deadlines for customers and supervisory authorities.
The document is not available yetData retention and deletion policy
Data categories, retention periods and how permanent deletion works.
The document is not available yetBusiness continuity and disaster recovery
Two-region infrastructure, failover, RTO/RPO and how the service behaves under degraded availability.
The document is not available yetAudomate terms of service
The agreement setting out the binding terms for using the Audomate platform.
Awaiting legal reviewData processing agreement
The processing terms, with annexes describing the security controls and the sub-processors. Signed for every deployment.
Request the documentDORA vendor documentation pack
Register of information data, incident notification rules, audit rights and termination terms.
Request the documentationRecord of processing activities and internal policies
The record of processing activities (RoPA) and the full internal security policy documentation.
Request accessReviewing us as a vendor? Send us your questionnaire.
We will complete it in your own format. We will say which controls are already in place and which are still planned. Security questions and vulnerability reports go to security@deeptech.pl.
Write to the teamContent last reviewed: 22-09-2026