Trust Center
itsAI runs on Danish infrastructure. The table below lists every control we promise — green when it's shipped, "coming soon" when it's on our roadmap. Logged-in users see the same status live at /safe; this page is the public mirror.
All itsAI data is stored on hardware physically located in Denmark — Digital Realty's Ballerup datacenter (Copenhagen). No third-country data transfers in the storage layer.
itsAI runs a shared schema that is hard-partitioned per customer: every read and write is filtered by your tenant ID in application code. Your data is never returned in another customer's query — isolation is enforced on the server, not trusted to the client.
Work is routed across many AI providers, chosen per task — your mail assistant, your embeddings, and your web lookups don't all go to the same place. So no single provider ever holds a complete picture of you. The full evaluated set is listed below.
Live status. Updates immediately when a control ships or its health changes.
| Data class | At rest today | In transit |
|---|---|---|
| Passwords | Argon2id with deployment pepper (no reversible storage) | TLS 1.2+ |
| OAuth + integration tokens | AES-256-GCM with ITSAI_ENCRYPTION_KEY | TLS 1.2+ |
| Session refresh tokens | SHA-256 hash; raw tokens never persisted | TLS 1.2+, HttpOnly + Secure + SameSite cookie |
| API keys | SHA-256 hash | TLS 1.2+ |
| Mail bodies, brain entries, attachments, scraped pages | Not yet column-encrypted (on the roadmap). Protected by tenant isolation, restricted access, and audit logging until then. | TLS 1.2+ |
| Backups | Backup-at-rest encryption on the roadmap. Backup media restricted to named operators. | TLS to the backup host |
Companies that process customer data on itsAI's behalf, outside of LLM inference (see the LLM provider set below for that). Each is bound by a data processing agreement. Changes are announced to controllers at least 30 days in advance via the DPA notification channel. The authoritative list — including the active LLM partners — lives in DPA Annex II.
| Sub-processor | Purpose | Region |
|---|---|---|
| it's IT A/S | Infrastructure hosting + SMTP relay | Denmark · EU |
| Cloudflare | Edge / CDN, Tunnel ingress, DDoS + WAF, DNS | Global edge · EU termination |
| Microsoft (MS Graph) | Optional — when you connect an Outlook / OneDrive / Calendar account | Customer-selected (typically EU) |
| Stripe | Billing + payment processing. Card data NEVER touches itsAI. | USA · EU subsidiary |
itsAI is built on the principle that no single LLM provider should see a complete picture of any user.Requests are routed across many providers — each chosen per task on capability, cost, latency, regional fit, and contractual non-training posture. Splitting the traffic this way means that even in the worst case where one provider were compromised, only a fragment of your work would be exposed.
Below are examples of the itsai.dk integrations — providers in the evaluated set. The specific subset active at any moment is operational and is not published; the formal list of active sub-processors at any given time is disclosed to controllers in DPA Annex IIand updated with 30 days' notice before any change.
If we become aware of a personal-data breach affecting your data, we notify you via email and an in-product banner within 48 hours of awareness — stricter than the 72 hours required by GDPR Article 33. Full terms in the DPA §4.6.
Security questions, vulnerability reports, breach disclosures, or controller-side compliance queries: privacy@itsai.dk. We acknowledge every report within one business day.