# Trust and security: built for teams that have to prove it

EU infrastructure, tenant isolation, encryption in transit and at rest, and a metadata-only audit trail. An honest account of where we stand on each standard.

## Built for teams that have to prove it.

Akumi runs on EU infrastructure, isolates every tenant, encrypts data in transit and at rest, and records a metadata-only audit trail of what happened. The controls you need to satisfy a security review are part of the platform, not an add-on you wire up.

## Security across the whole platform.

Controls are enforced in code on every request, not left to convention and not sold as a tier you upgrade into.

### Data residency

The application, the models and your data all run in the EU. A fail-closed egress guard blocks any non-EU routing unless you explicitly allow it.

### Tenant isolation

Every organization's data is scoped to that organization. One tenant's prompts, documents, memory and cache are never visible to another.

### Encryption

Traffic is encrypted in transit with TLS, and data is encrypted at rest. Secrets and provider keys are stored encrypted, never in plaintext.

### Access control

Role-based access with owner, admin and member roles. Enterprise adds SSO through OIDC and SAML, and user provisioning through SCIM.

### Enforced in code

The firewall and the routing policy run on every request, and each action is recorded. The controls are in the platform, not left to convention.

### Auditability

A metadata-only audit trail records what each request did, its model, region and services, never your prompts or content. Retention is bounded and pruned automatically.

## Privacy by design.

The platform is built to support your GDPR obligations: personal data in prompts is pseudonymized before it leaves, a single call erases an end-user's data, and the records you need for an audit are produced automatically. We act as your processor and stay honest about where your responsibilities remain.

### Pseudonymized before egress

The firewall replaces personal data with tokens before an external model call it covers, and restores them in the response. Embedding input is not firewalled: external embeddings are gated on residency and a recorded acceptance instead.

### Right to erasure

Delete an end-user's memory and data with one API call, wired into your own account-deletion flow.

### Data minimization

The audit trail holds metadata only: your prompts, completions and retrieved content are never in it. Traces hold what each stage was given only where a workspace keeps it, pseudonymized wherever the firewall runs.

### Sub-processors disclosed

The current list of sub-processors is published at akumi.eu/legal/sub-processors and forms part of the data processing agreement.

## Honest about where we are.

We will not point at a badge we have not earned. Here is the real posture, and where to get the detail.

### GDPR: Built in

The platform is built around GDPR controls: EU residency, pseudonymization, erasure and metadata-only records. A DPA sets out our role as your processor.

### EU AI Act: Built in

Architected for EU AI Act obligations as they take effect, with residency and auditability that support transparency and oversight requirements.

### DORA: Supported

If you fall under DORA, Akumi is an ICT third-party service provider you have to register. The sub-processor list, the DPA and per-request residency records give your register of information its entries and the evidence behind them.

### NIS2: Supported

NIS2 pushes security obligations down the supply chain to entities like us. Tenant isolation, access control, encryption and a named security contact are documented so you can evidence Akumi as a supplier without a questionnaire round-trip.

### ISO 27001: In progress

In progress, not certified yet. We are building the information security management system toward ISO 27001 and will publish the certificate when an accredited auditor issues one, not before.

## Ask, and tell us.

Two things a security reviewer usually needs: the documents, and a way to reach someone when they find a problem.

### Documentation on request

The sub-processor list is published at akumi.eu/legal/sub-processors. Security documentation and the DPA are shared with customers and prospects under review. Ask and we will send them.

### Found something? Tell us.

If you believe you have found a security vulnerability, report it to security@akumi.eu. We investigate every report, will not pursue good-faith research, and will keep you updated as we work a fix. We do not run a bug bounty: a report earns no payment and no public acknowledgement. Send the technical detail with the first message rather than asking what a finding is worth.

## Need the detail for a review?

Tell us what your security or procurement team needs, and we will get you the documentation.
