// Our security promise
Sicherheit bei Mindverse
Security is our fundamental promise — not an afterthought. An information security management system built to ISO 27001 keeps your data safe, your workspace private, and your information accurate: GDPR-compliant, encrypted, and hosted exclusively in Germany.
- ISMS
- built to ISO 27001:2022
- DPA
- EU SCC · Art. 28 GDPR
- Hosting
- 100% Germany
- policy_classification active
- policy_threat_incident_mgmt active
- policy_access_management active
- policy_secure_development active
- policy_operations active
- policy_cryptography active
- policy_business_continuity active
- policy_supplier_mgmt active
// Audited processes
We implement strict security protocols and verify their effectiveness in regular internal audits and penetration tests — accompanied by an external information security officer.
An external information security and data protection officer accompanies our ISMS. All details on data processing are in our privacy policy; our stance on responsible AI in our ethical principles.
// Protection goals
Three protection goals every measure has to answer to
Confidentiality, integrity, availability — C · I · A. Every rule and every technical measure in our ISMS exists to guarantee or improve these three goals.
Confidentiality
What you do not want to share with third parties stays confidential. Classification and protection needs of every piece of information are governed by a dedicated policy — from labeling and transport to retention.
Integrity
You make business decisions with our results. Information must therefore never be distorted by errors or negligence — integrity checks are part of how we build.
Availability
Systems have to deliver when you need them. Capacity management, backups and business-continuity plans keep the platform available — even when something goes wrong.
If any of the three goals is violated, it is a security incident — and triggers our incident management
// Defense in depth
Three lines of defense instead of one wall
There is no such thing as absolute security — whoever promises otherwise has not understood the problem. That is why we organize information security in multiple lines: prevent attacks, detect intruders early, and be prepared for the worst case.
The third line is a defense in itself: big attacks often start with a small disturbance meant to push teams into hectic ad-hoc work. Whoever has defined procedures keeps following well-thought-out rules — even then.
-
Line 01
Intrusion prevention
The first line keeps unauthorized parties out of the systems in the first place: hardening, network segmentation, access controls, encryption.
-
Line 02
Intrusion detection
The second line discovers and stops intruders early: monitoring, logging, and continuous observation of the entire platform.
-
Line 03
Incident response & BCM
The third line is preparation for the worst case: defined procedures, breach management, and business-continuity plans for a fast return to normal operations.
// Security architecture
Six pillars that protect your data
From the data center to the vector database: every layer of the platform is built for confidentiality, integrity, and traceability.
Data security
Row-level access controls separate information cleanly by role and organizational unit — everyone sees exactly what they are allowed to see, and nothing more.
Vulnerability scans
Regular scans and penetration tests at critical points in the development cycle identify potential weaknesses before they become a risk.
GDPR compliance
Secure processing, data processing agreements under Art. 28, and mechanisms to exercise your data-subject rights — from access to erasure.
Your data is never used for training
Your content, documents, and prompts are never used to train LLMs. What you enter stays yours.
Instance separation
Enterprise customers can get a dedicated LLM instance that is physically and logically isolated from other customer environments.
Dedicated prompting and vector database
Prompting methods and the vector database are tailored to your use cases — for precise answers with citations from your own knowledge bases.
// The ISMS behind it
A management system that is lived — not just written down
Our information security management system is built to ISO 27001:2022 and follows the 93 controls of its Annex A: organizational, people, physical, and technological. It is not certified by an accredited body; it is consistently run to the standard. The written order has three levels: a guideline sets the principles, policies govern the how, and procedures keep the implementation current.
Responsibility is assigned to roles — from asset owner to service manager. Conflicts of interest are ruled out where it matters: nobody reviews their own work. And because threats change, the ISMS changes with them — rules that do not help get fixed instead of filed.
KISS
Keep it simple
Complexity correlates negatively with security. Simple, clear systems are systems you can control.
DENY ALL
Blocked until allowed
Access is denied by default and granted deliberately — never the other way around.
4 EYES
Four-eyes principle
No code reaches production without an independent review — nobody reviews their own work.
ZERO TRUST
Trust is not a control
Every request is verified, every permission justified — inside our own systems too.
-
klassifizierung
Classification & protection needs
-
threat_incident
Threat & incident management
-
bcm
Business continuity
-
assets
Asset management
-
lieferanten
Supplier management
-
access
Access management
-
people
People controls
-
physical
Physical security
-
development
Secure development
-
operations
Operations
-
krypto
Cryptography & keys
-
compliance
Compliance & knowledge
12 policies · registers & inventories instead of case-by-case decisions · accompanied by an external ciso / dpo
// GDPR in detail
GDPR compliance you get in writing
Compliance must not be a marketing word. That is why we answer your data protection officer's questions before they are asked — with a data processing agreement under Art. 28 GDPR based on the EU standard contractual clauses, and documented processes for every data-subject right.
| Requirement | Basis | How Mindverse delivers |
|---|---|---|
| Data processing agreement | Art. 28 GDPR | Standardized DPA based on the EU standard contractual clauses (Implementing Decision 2021/915) — available on request at short notice. |
| Right of access | Art. 15 GDPR | Complete export of your data directly from the platform. |
| Right to erasure | Art. 17 GDPR | Documented deletion concepts; complete removal from all systems on request. |
| Breach notification | Art. 33/34 GDPR | Defined breach management: immediate notification with everything your report to the supervisory authority requires. |
| Data location | Hosting | Processing exclusively on servers in certified data centers in Germany. |
| Sub-processors | Transparency | Agreed list with advance notice of changes and a right to object — no hidden data flows. |
| Model training | Purpose limitation | Your content is never used to train AI models. |
// Hosting & sovereign models
Data in Germany — and, if you want, the AI models too
Mindverse Studio is hosted exclusively in Germany. With our sovereign models such as GPT OSS 120B and DeepSeek V3.2, even inference itself runs on German infrastructure on request — your data never leaves the EU. And because the platform is LLM-independent, you keep the choice of model: OpenAI, Anthropic, Google, and Mistral via EU endpoints, or fully sovereign.
How companies work with this at scale is covered on AI for companies — the available plans including the sovereign option are on the pricing page.
AES-256 encryption
Encryption in transit (TLS) and at rest — for documents, knowledge bases, and chat histories.
SOC 2-oriented processes
Security and control processes built on the SOC 2 framework: documented and verifiable — without an attested SOC 2 report.
Pentests & monitoring
Regular penetration tests, intrusion detection, and continuous monitoring across the entire platform.
RBAC, SSO & audit logs
Role-based access across company, team, and user levels, SSO via OIDC, and complete audit logs.
// Responsible AI
AI that passes the audit
Secure AI does not end at the infrastructure. Protection against prompt injection, output filters, and per-team model policies keep AI results controllable. As a signatory of the Hamburg Declaration on Responsible AI, we publicly commit to transparent, responsible AI development.
- Protection against prompt injection and misuse
- Answers with citations from your knowledge bases
- Human-in-the-loop approvals in workflows
- Model policies and permissions per team
More on how citations work under texts with citations and knowledge bases.
// From practice
Secure AI process automation in practice: communications agency media.works saves over 40% of its time with Mindverse — in full GDPR compliance.
// Persona · Integrated pseudonymisation
Protect sensitive details before they reach the LLM.
A fine-tuned model detects personal details in context and replaces them with consistent pseudonyms. Explore pseudonymisation in Mindverse Studio, with nine data categories and re-identification for usable responses.
// FAQ
Frequently asked security questions
What security measures does Mindverse use?
How does Mindverse protect my data?
Is Mindverse GDPR-compliant?
Is my data shared with third parties?
Which certifications does Mindverse hold?
How does Mindverse secure its AI models?
Are there audits or reviews of the security standards?
Is my data deleted after use?
Is the Mindverse platform protected against cyberattacks?
How is it ensured that the AI does not process sensitive data?
// Start securely
Try the secure, GDPR-compliant AI suite
Boost your productivity without compromising on data protection — free for 7 days, hosted in Germany.
GDPR-COMPLIANT · SERVERS IN GERMANY · SOC 2-ORIENTED PROCESSES