Skip to contentNewChat and Code are in previewJoin the waitlist

Trust and security

Built for teams that have to prove it.

Akumi runs on EU infrastructure, isolates every tenant, encrypts data in transit and at rest, and records a metadata-only audit trail of what happened. The controls you need to satisfy a security review are part of the platform, not an add-on you wire up.

What is enforced

Security across the whole platform.

Controls are enforced in code on every request, not left to convention and not sold as a tier you upgrade into.

  • Data residency

    The application, the models and your data all run in the EU. A fail-closed egress guard blocks any non-EU routing unless you explicitly allow it.

  • Tenant isolation

    Every organization's data is scoped to that organization. One tenant's prompts, documents, memory and cache are never visible to another.

  • Encryption

    Traffic is encrypted in transit with TLS, and data is encrypted at rest. Secrets and provider keys are stored encrypted, never in plaintext.

  • Access control

    Role-based access with owner, admin and member roles. Enterprise adds SSO through OIDC and SAML, and user provisioning through SCIM.

  • Enforced in code

    The firewall and the routing policy run on every request, and each action is recorded. The controls are in the platform, not left to convention.

  • Auditability

    A metadata-only audit trail records what each request did, its model, region and services, never your prompts or content. Retention is bounded and pruned automatically.

Your GDPR obligations

Privacy by design.

The platform is built to support your GDPR obligations: personal data in prompts is pseudonymized before it leaves, a single call erases an end-user's data, and the records you need for an audit are produced automatically. We act as your processor and stay honest about where your responsibilities remain.

GDPR compliance EU data residency

Pseudonymized before egress
The firewall replaces personal data with tokens before an external model call it covers, and restores them in the response. Embedding input is not firewalled: external embeddings are gated on residency and a recorded acceptance instead.
Right to erasure
Delete an end-user's memory and data with one API call, wired into your own account-deletion flow.
Data minimization
The audit trail holds metadata only: your prompts, completions and retrieved content are never in it. Traces hold what each stage was given only where a workspace keeps it, pseudonymized wherever the firewall runs.
Sub-processors disclosed
The current list of sub-processors is published at akumi.eu/legal/sub-processors and forms part of the data processing agreement.

Where we actually stand

Honest about where we are.

We will not point at a badge we have not earned. Here is the real posture, and where to get the detail.

GDPRBuilt in
The platform is built around GDPR controls: EU residency, pseudonymization, erasure and metadata-only records. A DPA sets out our role as your processor.
EU AI ActBuilt in
Architected for EU AI Act obligations as they take effect, with residency and auditability that support transparency and oversight requirements.
DORASupported
If you fall under DORA, Akumi is an ICT third-party service provider you have to register. The sub-processor list, the DPA and per-request residency records give your register of information its entries and the evidence behind them.
NIS2Supported
NIS2 pushes security obligations down the supply chain to entities like us. Tenant isolation, access control, encryption and a named security contact are documented so you can evidence Akumi as a supplier without a questionnaire round-trip.
ISO 27001In progress
In progress, not certified yet. We are building the information security management system toward ISO 27001 and will publish the certificate when an accredited auditor issues one, not before.

Getting the detail

Ask, and tell us.

Two things a security reviewer usually needs: the documents, and a way to reach someone when they find a problem.

  • Documentation on request

    The sub-processor list is published at akumi.eu/legal/sub-processors. Security documentation and the DPA are shared with customers and prospects under review. Ask and we will send them.

    Read the DPA
  • Found something? Tell us.

    If you believe you have found a security vulnerability, report it to security@akumi.eu. We investigate every report, will not pursue good-faith research, and will keep you updated as we work a fix. We do not run a bug bounty: a report earns no payment and no public acknowledgement. Send the technical detail with the first message rather than asking what a finding is worth.

    security@akumi.eu

Need the detail for a review?

Tell us what your security or procurement team needs, and we will get you the documentation.