Data security & confidentiality

Your data stays yours.

SOPs, audit reports and training results are confidential. Five technical layers ensure other clients, partners or the AI vendor can never reach them.

5 layers of protection

01

Database isolation

Row-Level Security in PostgreSQL — other clients can technically never reach your data, not even through faulty queries.

02

Server-side AI calls

The browser never talks to Claude directly. For each question, the server builds a request containing only your documents and context.

03

Invisible configuration

API keys and system prompts live on the server. Not in the browser, not copyable, not modifiable by users.

04

Prompt-injection protection

Every AI agent carries instructions against extraction attempts. And: other tenants are simply never in the context.

05

Anthropic under a DPA

No training on your data. EU/US routing under a data processing agreement, GDPR-compliant.

Commitments

What we guarantee
  • No access for other clients or partners
  • No training by Anthropic on your data
  • EU hosting (Supabase EU), TLS 1.3, bcrypt
  • Data processing agreements with all subprocessors
  • Right of access, rectification and erasure (GDPR)
What is accessible
  • Your own employees — only their own data
  • Your quality manager — results within your own organisation
  • Your partner consultant — agent configuration, under NDA
  • RealAxces (support) — under NDA and GDPR
  • Anthropic — only during the API call, no storage for training

A question from practice

"Could someone use Claude to pull our SOPs or audit reports out of your platform?"

No. Other clients' documents are never part of the AI request. Database isolation + server-side context building make cross-tenant extraction technically impossible.

Questions about security?

Ask them directly

Want to review the data processing agreement, walk through the architecture, or raise a specific audit question? A first conversation is free of obligation and concrete.

FRANK@REALAXCES.NL