Data security & confidentiality
Your data stays yours.
SOPs, audit reports and training results are confidential. Five technical layers ensure other clients, partners or the AI vendor can never reach them.
5 layers of protection
Database isolation
Row-Level Security in PostgreSQL — other clients can technically never reach your data, not even through faulty queries.
Server-side AI calls
The browser never talks to Claude directly. For each question, the server builds a request containing only your documents and context.
Invisible configuration
API keys and system prompts live on the server. Not in the browser, not copyable, not modifiable by users.
Prompt-injection protection
Every AI agent carries instructions against extraction attempts. And: other tenants are simply never in the context.
Anthropic under a DPA
No training on your data. EU/US routing under a data processing agreement, GDPR-compliant.
Commitments
- ✓No access for other clients or partners
- ✓No training by Anthropic on your data
- ✓EU hosting (Supabase EU), TLS 1.3, bcrypt
- ✓Data processing agreements with all subprocessors
- ✓Right of access, rectification and erasure (GDPR)
- Your own employees — only their own data
- Your quality manager — results within your own organisation
- Your partner consultant — agent configuration, under NDA
- RealAxces (support) — under NDA and GDPR
- Anthropic — only during the API call, no storage for training
A question from practice
No. Other clients' documents are never part of the AI request. Database isolation + server-side context building make cross-tenant extraction technically impossible.
Questions about security?
Ask them directly
Want to review the data processing agreement, walk through the architecture, or raise a specific audit question? A first conversation is free of obligation and concrete.
FRANK@REALAXCES.NL