Resources

Frequently asked questions

Answers to common questions about Xalerate — governance, data residency, models, security and getting started.

What is Xalerate?

Xalerate is a governed AI platform for companies — one place to use approved AI models for everyday work, with policy, audit and European data handling built in. It brings model choice, governed knowledge and agent oversight together so teams get more from AI without building around any single provider.

What are the products?

Chat is the front door — a professional AI workspace your team uses day to day. Memory is the governed, access-controlled knowledge layer teams and agents share. Gateway is the model-routing platform underneath — policy-based provider choice, per-request audit and portability across model vendors. (Chat is in internal beta and some capabilities are waitlist — see "getting started".)

Where is our data processed and stored?

In the EU. Storage — database, backups and logs — is in the EU (Netherlands). Inference is per-tier: EU-owned providers, an EU-cloud region, and an optional unrestricted tier you can turn on that may route outside the EU — disclosed per model. The region shown for a tier is the region configured for it.

Do you train on our data?

No. Xalerate does not train on your data. Model providers run under their own terms, and we do not make a blanket claim on their behalf — some providers' terms permit them to use content you submit. The direct Moonshot Kimi model on the unrestricted tier is one such case: it is opt-in by name, clearly flagged, and carries a do-not-send warning for personal or regulated data.

Is Xalerate GDPR-compliant / SOC 2 / ISO 27001 certified?

Xalerate AB is an EU (Swedish) company built for GDPR — EU hosting, a DPA available, and support for data-subject rights. We say "built for GDPR", not "certified compliant" — final compliance is your legal team's determination. We are not SOC 2 or ISO 27001 certified; a SOC 2 evidence program is in evaluation and we don't claim a report exists. Our Security page details the current posture.

Which AI models can we use, and can we bring our own keys?

Xalerate routes across multiple providers so you're not locked to one model vendor — you route each request by cost, quality, latency and data location, with a full audit trail. You can bring your own provider keys and switch providers at any time.

What does "every answer is governed and recorded" mean?

Every answer comes with a receipt: which model ran, why it was chosen, what it cost, and where the data went — a structured record tied to a named person, built for auditors, reviews and incident response. A tamper-evident, signed audit ledger is in progress.

How is Xalerate positioned on the EU AI Act?

Xalerate is designed with the EU AI Act in mind — governance, audit evidence and European data handling are built in rather than bolted on. It supports your AI-Act obligations (classification inputs, audit trail, per-request records); it does not replace your own compliance assessment.

How do we get started?

Join the waitlist or book a demo. Pricing is not yet published — tell us what you need and we'll talk it through.

Still have a question? Ask us anything or see the Trust Center and Security pages.