Security isn't a feature. It's the whole product.

Tisser is built for teams that can't trade control for speed. Every architectural choice is weighed against the GDPR and the EU AI Act — because you're trusting us with customer data, brand assets and claims that carry real risk. This page makes the choices explicit, and names the ones that belong to our provider rather than to us.

A man at a desk by a tall office window, looking out
“The question isn't whether AI is safe. It's who can reach your data, where it goes, and whether you can prove what happened to it.”

The concrete choices, not the slogans.

No sovereignty-washing. These are the architectural decisions your team can hold us to — and the ones your compliance officer will ask about first. Where the evidence is someone else's document, we say whose.

01

Certified infrastructure & EU hosting

The platform runs on Google Cloud infrastructure in the EU, and that infrastructure is ISO 27001 certified. We want to be exact about what that means: the certificate is Google's, for the data centres. Neither Tisser nor Artific holds an ISO 27001 certificate of its own, and we will not imply otherwise. Your data sits under European law.

02

Encryption & access management

Everything sent to the platform is encrypted in transit, and databases use encryption at rest with AES-256 or better. Authentication runs on Firebase Authentication, itself certified to ISO 27001, 27017 and 27018 and SOC 1, 2 and 3 — again, Google's certificates, for that service. Passwords are stored hashed and cannot be read by anyone. Database and API credentials are restricted to the developers who maintain the systems, and source-code access is limited to named accounts so every change is traceable.

03

Privacy by Design & Default

In line with GDPR Art. 5 and 25, privacy is the starting point, not an afterthought. The default settings are the most privacy-protective ones; anything more open requires an explicit, deliberate choice. Privacy risk is assessed at each stage of development.

04

Least-privilege retrieval

When an agent calls a language model, retrieval hands it the passages the task needs rather than a whole record. Each call is kept to the minimum it can work with, which limits exposure and makes the output easier to explain. It is an access measure, not an encryption one — we say so below.

05

Data Processing Agreement

Every customer signs a Data Processing Agreement under GDPR Art. 28 — processing purposes, retention, sub-processors and breach handling. The upstream agreement with our platform provider is public, and we summarise it clause by clause on the Legal page rather than asking you to take our word for it.

06

Built for the EU AI Act

We classify our AI uses, document the risks, and build in human oversight, transparency and explainability at every agent — the same publish gate you see across the product. We say built for, not compliant with: the Act phases in over several years and there is no conformity scheme covering most of it yet.

Architecture · the data journey

What happens between “ask” and “answer”.

Our data architecture is built in clearly separated layers. At every layer, integrity, authorisation and traceability come first.

The data journey, and the tenant boundary Sign-in, retrieval, result and storage all happen inside your tenant in the EU. Only the model call crosses the boundary to OpenAI or Vertex AI, carrying just the passages the task needs, and the completion comes back. YOUR TENANT · EU MODEL PROVIDER TENANT BOUNDARY 01 Sign-in, inside your tenant Authenticated session · Google or Microsoft 02 Retrieval, split by context Only the passages the task needs, scoped to the role 03 OpenAI / Vertex AI EU region 04 Result returned to your tenant Back inside your own environment 05 Stored encrypted AES-256 at rest, backed up automatically what the task needs the completion
Only step 03 leaves your tenant, and it carries the passages the task needs rather than the whole record — encrypted in transit. Identifiers are not stripped before that call.

On context-splitting

Retrieval hands the model the passages a task needs rather than a whole record, which keeps any single call to the minimum it can work with and makes the output easier to explain. It is a least-privilege measure, not an encryption one: what does reach the model provider reaches it in readable form, governed by the contract rather than by the splitting.

Technical & organisational measures

What is actually in the contract.

These are the measures set out in annex 2 of the published processing agreement our platform provider works under — the document itself, not a marketing summary of it.

Measure What it means
Encryption in transitEverything users send is encrypted, both back-end configuration and end-user interaction, so it is unreadable if intercepted.
Encryption at restDatabases use encryption at rest with AES-256 or better.
AuthenticationFirebase Authentication. Google and Microsoft sign-in is used for identification only; no personal data is shared with them.
Role-based rightsRights management inside the application determines which users get which level of access.
Restricted credentialsDatabase and API access codes are available only to the developers responsible for building and maintaining the systems.
Traceable source codeCodebase access is limited to named employee accounts, so every change traces back to a person.
Updates & patchingServers, libraries and software receive regular updates and security patches.
Automated back-upsRegular automated back-ups of all data, stored securely, against outage, leak or attack.

Trust triangle · three parties, one accountability

Clear roles, shared responsibility.

Tisser, Artific and you form one arrangement — with you as a full partner in security, not a bystander to it.

Product & guidance

Tisser

Product, implementation, integration, training and advice. We translate the technology into how your marketing, sales and support teams actually work. AIO B.V., trading as Tisser, is your contracting party.

Backend & inference

Artific

Backend and inference provider, engaged as our sub-processor. Builds and runs the underlying AI infrastructure on certified Google Cloud servers in the EU, model-agnostic, under a published processing agreement.

Data & scrutiny

You

You are the controller. You supply high-quality data and hold us to account with your own Data Protection Impact Assessments (DPIAs). That scrutiny is how the platform stays as safe as it can be.

Model-agnostic

Swap GPT, Claude, Gemini or another model per agent, per task, per tenant — no lock-in to a single provider, and every model runs under the same contract and the same access controls. It's the same model-picker you see on the Tisser One page, governed by the security described here.

Frequent questions

What compliance officers ask first.

The questions we answer before anyone wants to talk about rollout.

Is our data used to train AI models?
Our platform provider states that data sent to OpenAI is not used for training purposes. For Vertex AI it confirms the integration but publishes no equivalent statement, so we are having that put in writing rather than assuming it. If a contractual no-training commitment across every model you use is a requirement for you, say so and we will make it an explicit term of your agreement.
Where does the data physically sit?
On Google Cloud infrastructure in the EU, so your data falls under European law. The processing agreement commits the processor to aim to keep processing within the EEA — as published, an obligation of effort rather than an absolute guarantee. Model providers and other sub-processors are listed on the Legal page, including what their published annex does and does not say about location.
What happens in a data breach?
You are informed without undue delay, with the nature and cause, the categories and number of people affected, the likely consequences and the remedial measures. Under GDPR Art. 33 the notification to the supervisory authority is the controller's decision and the controller's act — yours. The 72-hour clock is yours; our job is to get you what you need inside it.
Can we get our data back, or have it destroyed?
Yes. Within 30 days of the agreement ending, personal data is returned to you or destroyed, at your choice, unless a statutory retention period applies. Remaining copies and back-ups are destroyed at a moment you set.
How does role-based access work?
Rights management inside the application determines which users reach which modules and which data. Authentication runs on Firebase Authentication, with Google or Microsoft sign-in supported for identification. If you need full enterprise SSO federation with your own identity provider, raise it early — we will confirm what is available for your tenant rather than assume it.
Do you use sub-processors?
Yes. The published annex names OpenAI, Vertex AI, Perplexity.ai and LangChain Inc., alongside Google Cloud for hosting. We reproduce that list unedited, with what it does and does not state about each one, on the Legal page. Changes are notified in advance and you have seven days to object.

Have a security question? Talk to the people who built it.

Deep technical or compliance questions — architecture, DPIAs, the DPA — get a real answer from the team responsible for it, not a sales script.

Or write to compliance@tisser.ai

Talk to a human