Trust and security
Built for teams that have to prove it.
Akumi runs on EU infrastructure, isolates every tenant, encrypts data in transit and at rest, and records a metadata-only audit trail of what happened. The controls you need to satisfy a security review are part of the platform, not an add-on you wire up.
What is enforced
Security across the whole platform.
Controls are enforced in code on every request, not left to convention and not sold as a tier you upgrade into.
Data residency
The application, the models and your data all run in the EU. A fail-closed egress guard blocks any non-EU routing unless you explicitly allow it.
Tenant isolation
Every organization's data is scoped to that organization. One tenant's prompts, documents, memory and cache are never visible to another.
Encryption
Traffic is encrypted in transit with TLS, and data is encrypted at rest. Secrets and provider keys are stored encrypted, never in plaintext.
Access control
Role-based access with owner, admin and member roles. Enterprise adds SSO through OIDC and SAML, and user provisioning through SCIM.
Enforced in code
The firewall and the routing policy run on every request, and each action is recorded. The controls are in the platform, not left to convention.
Auditability
A metadata-only audit trail records what each request did, its model, region and services, never your prompts or content. Retention is bounded and pruned automatically.
Your GDPR obligations
Privacy by design.
The platform is built to support your GDPR obligations: personal data in prompts is pseudonymized before it leaves, a single call erases an end-user's data, and the records you need for an audit are produced automatically. We act as your processor and stay honest about where your responsibilities remain.
- Pseudonymized before egress
- The firewall replaces personal data with tokens before an external model call it covers, and restores them in the response. Embedding input is not firewalled: external embeddings are gated on residency and a recorded acceptance instead.
- Right to erasure
- Delete an end-user's memory and data with one API call, wired into your own account-deletion flow.
- Data minimization
- The audit trail holds metadata only: your prompts, completions and retrieved content are never in it. Traces hold what each stage was given only where a workspace keeps it, pseudonymized wherever the firewall runs.
- Sub-processors disclosed
- The current list of sub-processors is published at akumi.eu/legal/sub-processors and forms part of the data processing agreement.
Where we actually stand
Honest about where we are.
We will not point at a badge we have not earned. Here is the real posture, and where to get the detail.
- GDPRBuilt in
- The platform is built around GDPR controls: EU residency, pseudonymization, erasure and metadata-only records. A DPA sets out our role as your processor.
- EU AI ActBuilt in
- Architected for EU AI Act obligations as they take effect, with residency and auditability that support transparency and oversight requirements.
- DORASupported
- If you fall under DORA, Akumi is an ICT third-party service provider you have to register. The sub-processor list, the DPA and per-request residency records give your register of information its entries and the evidence behind them.
- NIS2Supported
- NIS2 pushes security obligations down the supply chain to entities like us. Tenant isolation, access control, encryption and a named security contact are documented so you can evidence Akumi as a supplier without a questionnaire round-trip.
- ISO 27001In progress
- In progress, not certified yet. We are building the information security management system toward ISO 27001 and will publish the certificate when an accredited auditor issues one, not before.
Getting the detail
Ask, and tell us.
Two things a security reviewer usually needs: the documents, and a way to reach someone when they find a problem.
Documentation on request
The sub-processor list is published at akumi.eu/legal/sub-processors. Security documentation and the DPA are shared with customers and prospects under review. Ask and we will send them.
Read the DPAFound something? Tell us.
If you believe you have found a security vulnerability, report it to security@akumi.eu. We investigate every report, will not pursue good-faith research, and will keep you updated as we work a fix. We do not run a bug bounty: a report earns no payment and no public acknowledgement. Send the technical detail with the first message rather than asking what a finding is worth.
security@akumi.eu
Need the detail for a review?
Tell us what your security or procurement team needs, and we will get you the documentation.