Akumi runs on EU infrastructure, isolates every tenant, encrypts data in transit and at rest, and records a metadata-only audit trail of what happened. The governance you need to satisfy a security review is part of the platform, not an add-on you wire up.
The application, the models, and your data all run in the EU. A fail-closed egress guard blocks any non-EU routing unless you explicitly allow it.
Every organization's data is scoped to that organization. One tenant's prompts, documents, memory, and cache are never visible to another.
Traffic is encrypted in transit with TLS, and data is encrypted at rest. Secrets and provider keys are stored encrypted, never in plaintext.
Role-based access with owner, admin, and member roles. Enterprise adds SSO through OIDC and SAML, and user provisioning through SCIM.
The PII firewall, guard, and routing policy run on every request, and each action is recorded. Controls are enforced in code, not left to convention.
A metadata-only audit trail records what each request did, its model, region, and modules, never your prompts or content. Retention is bounded and pruned automatically.
The platform is built to support your GDPR obligations: personal data is pseudonymized before it leaves, a single call erases an end-user's data, and the records you need for an audit are produced automatically. We act as your processor and stay honest about where your responsibilities remain.
We will not point at a badge we have not earned. Here is the real posture, and where to get the detail.
If you believe you have found a security vulnerability, report it to [email protected]. We investigate every report, will not pursue good-faith research, and will keep you updated as we work a fix.
Tell us what your security or procurement team needs, and we will get you the documentation.
We use privacy-friendly, EU-hosted analytics to understand how Akumi is used. Accept analytics cookies, or continue without them. See our cookie policy.