Security & compliance

Built for regulated organisations.

Your data stays in the EU or in your own data centre. Every answer is evidenced, logged and approved by people before anything goes out.

Deployment

EU cloud, your data centre or air-gapped

You choose where c:node runs: as your own tenant in the EU cloud in Frankfurt, entirely on your servers or without any internet connection.

Access

You approve what c:node may see

Connectors work with the access you approve. API keys are bound to a profile and your tenant – nothing reaches beyond your tenant.

AI safety

Approved models, verified statements

You decide which models are approved. Every statement is checked against its source; anything that cannot be evidenced is marked as open instead of asserted.

Proof

Every answer in the audit trail

Answer, sources, verification result and approval go into the log, with a content hash. Auditable for internal audit and regulators – built for the logging obligations of the EU AI Act (Art. 12).

Human oversight

Nothing goes out without approval

Agents prepare – emails, official notices, CRM entries. Nothing is executed until you approve. That way, the decision stays with people.

Where does our data run – and who sees it?
A short summary for your tenant:
Security · overview
DeploymentEU cloud · Frankfurt
TenantYour own, separated
Check against sourceEvery answer
Audit trailActive
Outbound actionsOnly with approval
Training on your dataNo
Can we also run c:node completely without internet?
Yes. You have three deployment modes – agents, connectors and evidence stay the same:
Deployment · options
EU cloudYour own tenant in Frankfurt
Your data centreOn your servers, with your models
Air-gappedNo internet, open models
What do you have access to at our company?
Only what you have approved:
Access · your tenant
Microsoft 365OAuth · read only
SalesforceOAuth · write with approval
Lexware OfficeAPI key · read only

Credentials are stored as a reference in your tenant's secret store.

Which AI models may see our data?
Only the ones you have approved – and I check every statement against its source:
Models · approved
Mistral Large 3approved
Claude Sonnet 5.5approved, EU region
Qwen · own serversapproved
GPT-6 Solnot approved
Show me today's audit trail.
Four entries, each with sources and content hash:
Audit trail · today
09:12Answer AML check · 5 sources
09:14Draft request for documents · pending
09:21Approved by M. Schulz
09:30Extract for internal audit
@Nora, prepare the notice for Ms K.
The notice is prepared – every statement names the provision and the evidence:
Draft · housing benefit notice Ms K.
Legal basis: WoGG § 3, § 4 · SGB I § 60
ApproveEditNothing goes out without approval
Legal

All documents in one place.

The binding texts on data protection, data processing and AI use.

Your security questions, answered.

We go through your requirements with IT security and data protection – before the first record.

Built for & funded byGDPREU AI ActBSFZ · research allowanceFunded by the BMFTR
FAQ

Security, briefly explained.

Anything else? Write to us.

Where is our data stored?

In your own tenant in the EU cloud in Frankfurt or entirely in your data centre – without internet if you wish. You decide before launch.

Is our content used to train AI models?

No. Your content is not used to train models.

Which AI models may see our data?

Only the ones you allow: models from EU providers, large models via API in the EU region or open models on your own servers.

How does c:node prevent made-up answers?

Every statement is checked against its source. Anything that cannot be evidenced is marked as open – c:node then says which information is missing.

Can an agent send emails or change data on its own?

No. Agents prepare drafts. Nothing goes out until an authorised person approves it.

Is c:node EU AI Act compliant?

c:node is built for the requirements of the EU AI Act: traceable answers, logging (Art. 12) and human oversight. We clarify the classification of your specific use case together with you.

Do we get a data processing agreement?

Yes. You'll find the DPA under Art. 28 GDPR in the legal section; separate agreements apply to on-prem deployments.