Trust Center

Your data. Verifiable, not assumed.

itsAI runs on Danish infrastructure. The table below lists every control we promise — green when it's shipped, "coming soon" when it's on our roadmap. Logged-in users see the same status live at /safe; this page is the public mirror.

EU data residency

All itsAI data is stored on hardware physically located in Denmark — Digital Realty's Ballerup datacenter (Copenhagen). No third-country data transfers in the storage layer.

Tenant isolation

itsAI runs a shared schema that is hard-partitioned per customer: every read and write is filtered by your tenant ID in application code. Your data is never returned in another customer's query — isolation is enforced on the server, not trusted to the client.

No single provider sees everything

Work is routed across many AI providers, chosen per task — your mail assistant, your embeddings, and your web lookups don't all go to the same place. So no single provider ever holds a complete picture of you. The full evaluated set is listed below.

Controls inventory

Live status. Updates immediately when a control ships or its health changes.

Loading…

Encryption

Data classAt rest todayIn transit
PasswordsArgon2id with deployment pepper (no reversible storage)TLS 1.2+
OAuth + integration tokensAES-256-GCM with ITSAI_ENCRYPTION_KEYTLS 1.2+
Session refresh tokensSHA-256 hash; raw tokens never persistedTLS 1.2+, HttpOnly + Secure + SameSite cookie
API keysSHA-256 hashTLS 1.2+
Mail bodies, brain entries, attachments, scraped pagesNot yet column-encrypted (on the roadmap). Protected by tenant isolation, restricted access, and audit logging until then.TLS 1.2+
BackupsBackup-at-rest encryption on the roadmap. Backup media restricted to named operators.TLS to the backup host

Sub-processors (infrastructure)

Companies that process customer data on itsAI's behalf, outside of LLM inference (see the LLM provider set below for that). Each is bound by a data processing agreement. Changes are announced to controllers at least 30 days in advance via the DPA notification channel. The authoritative list — including the active LLM partners — lives in DPA Annex II.

Sub-processorPurposeRegion
it's IT A/SInfrastructure hosting + SMTP relayDenmark · EU
CloudflareEdge / CDN, Tunnel ingress, DDoS + WAF, DNSGlobal edge · EU termination
Microsoft (MS Graph)Optional — when you connect an Outlook / OneDrive / Calendar accountCustomer-selected (typically EU)
StripeBilling + payment processing. Card data NEVER touches itsAI.USA · EU subsidiary

LLM provider set

itsAI is built on the principle that no single LLM provider should see a complete picture of any user.Requests are routed across many providers — each chosen per task on capability, cost, latency, regional fit, and contractual non-training posture. Splitting the traffic this way means that even in the worst case where one provider were compromised, only a fragment of your work would be exposed.

Below are examples of the itsai.dk integrations — providers in the evaluated set. The specific subset active at any moment is operational and is not published; the formal list of active sub-processors at any given time is disclosed to controllers in DPA Annex IIand updated with 30 days' notice before any change.

Frontier model providers

  • 01.AI
  • Aleph AlphaEU · DE
  • Alibaba Qwen
  • Anthropic
  • Cohere
  • DeepSeek
  • Google Gemini
  • Inflection
  • Meta Llama
  • Mistral AIEU · FR
  • OpenAI
  • Perplexity
  • Reka AI
  • xAI

Inference + hosting

  • AWS Bedrock
  • Azure AI Foundry
  • Fireworks AI
  • Groq
  • Hugging Face Inference
  • LightOnEU · FR
  • OpenRouter
  • Replicate
  • Together AI

Embeddings + specialised

  • Jina AI
  • NVIDIA NIM
  • Snowflake Cortex
  • Voyage AI
  • IBM watsonx
The set evolves. Selection is automatic and per-task; users do not choose a provider directly. This is a non-exhaustive sample — the full active list at any moment lives in DPA Annex II.

Breach notification commitment

If we become aware of a personal-data breach affecting your data, we notify you via email and an in-product banner within 48 hours of awareness — stricter than the 72 hours required by GDPR Article 33. Full terms in the DPA §4.6.

Security contact

Security questions, vulnerability reports, breach disclosures, or controller-side compliance queries: privacy@itsai.dk. We acknowledge every report within one business day.