Employee communication means sensitive data. We take it seriously at every level: from EU hosting and GDPR compliance, through encryption, two-factor authentication and round-the-clock monitoring, to private AI that takes no data outside.
Servers and data kept in data centres within the European Union, in line with GDPR requirements.
With every client we sign a data processing agreement that clearly defines the scope and responsibilities of each party.
The AI assistant can run on your infrastructure — data and documents do not go to OpenAI or any other external company.
The option to deploy on your infrastructure and a source-code licence — full control and no vendor lock-in (a clear exit scenario).
Infrastructure hosted in ISO 27001-certified data centres (OVHcloud) — the certification covers the provider's infrastructure.
All communication between app and server is encrypted with the latest HTTPS / TLS 1.3 standard.
Data stored on servers is encrypted with AES-256.
Enforced HTTPS (HSTS) and a set of protective headers: Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy.
An extra layer of verification at login, protecting accounts from unauthorised access.
Login via a corporate account using OIDC / OAuth, with automatic locking of inactive sessions.
Access tokens stored server-side and revoked instantly, complemented by cryptographic request signing (integrity).
Role-based access to content — administrator, super-administrator, management per country and site.
A firewall protecting the infrastructure; administrative access limited strictly to authorised people.
Continuous infrastructure monitoring and security incident detection in a SIEM-class system.
An AI agent monitors servers around the clock and detects intrusion attempts, and runs automatic updates every night — with a daily security report.
Regular penetration tests carried out by independent specialists.
Automatic backups performed every 12 hours, with monitoring of their completion.
Regular system updates and ongoing vulnerability management.
Services maintained at 99.9% availability, with continuous monitoring of operation.
Service restored within 12 hours of an outage; RPO and RTO of 12 hours.
The app does not reach into private data on the employee's phone — it operates within its own company content.
A production worker can use the app without a company email — logging in via QR code or in kiosk mode.
Phone number and private email are not required — we collect only the data necessary for the app to work.
The employee can mute notifications outside working hours — peace during private time.
The ability to report and moderate offensive content posted in the app.
Regular team training on security and data protection principles.
Antivirus protection on the team's workstations.
We maintain formal security documentation and rely on recognised industry standards. Because of its confidential nature we share it after verification — leave your contact details and we'll get in touch and provide the selected documents.
Data protection rules, responsibilities, IT safeguards and incident handling. Available on request.
Rules for securely managing the IT system that processes personal data. Available on request.
An assessment of risks to data processed in the app, carried out under Art. 32 GDPR. Available on request.
Fulfilment of information obligations towards the people whose data we process. Available on request.
The team's commitment to keep entrusted data confidential. Available on request.
Results of independent security tests of the infrastructure and application. Available on request.
During a demo we'll show the technical details, architecture and data handling using your company as an example.
Let's talk