Trust center

Security questionnaire.

Straight answers to the questions buyers, security teams and auditors ask — stated against what’s real today. Where something is still being built, we say so. Xalerate provides technical controls and evidence; it doesn’t, on its own, grant legal compliance.

Questionnaire

Security & privacy posture.

Answers are labelled: unmarked = in place today; “In progress” = being built; “Pending review” = not yet cleared for publication.

Company & compliance

Legal entity & location
Xalerate AB, registered in Sweden (EU).
SOC 2 / ISO 27001In progress
Not certified. A SOC 2 control-governance and evidence program is in evaluation — the observation window has not started. We don’t claim a report exists.
GDPR
Built for GDPR: EU entity, EU hosting, a DPA available, and support for data-subject rights. We say “built for GDPR”, not “certified compliant” — final compliance is your legal team’s determination.
Data Processing Agreement (DPA)Pending review
A DPA (GDPR Art. 28) is available on request.

Data residency & sovereignty

Where is data processed & stored?
In the EU. Inference residency is per-tier: eu_strict (EU-owned providers), eu_sweden (EU storage: Netherlands, disclosed per leg), eu_cloud (EU region), and unrestricted (customer-configurable). Storage — database, backups, logs — is EU (Netherlands). The region shown for a tier is the region configured for it.
Cross-border transfers
EU tiers stay in the EU. The unrestricted tier may route outside the EU only when you select it, and it’s disclosed per model.
Sub-processors
See the sub-processor list further down this page.

Data protection & encryption

Encryption in transit
TLS.
Encryption at restIn progress
Disk-level encryption (managed Postgres + object storage). Field/column-level encryption is on the roadmap and not yet implemented.
Key managementPending review
Details available on request.

Access control & authentication

SSO / OIDC / SAML
OIDC / SSO is available; enforcement is configurable (not on by default).
MFAPending review
Available via your identity provider when SSO is used.
RBAC / least privilege
Role-based access (organization roles + permission checks), with least-privilege database roles and a fail-closed runtime preflight.

Tenant isolation

How is tenant data isolated?
Postgres Row-Level Security (enabled and forced, fail-closed, with a dedicated bypass-role split) on the multi-tenant services; app-layer user-scoping and explicit ownership checks elsewhere. Independently audited.

Audit logging & monitoring

Audit logs
Per-request audit logging — the data region is recorded on each request, and the region shown for a tier is the region configured for it. A tamper-evident, signed (hash-chained) audit ledger is in progress.
Monitoring & alertingIn progress
Per-service observability (structured logs with trace IDs, golden-signal metrics, threshold alerts) is live and rolling out; a centralized alerting plane is in build.

AI & model data handling

Do you train on customer data?
Xalerate does not train on your data. Model providers run under their own terms, and we do not make a blanket claim on their behalf — some providers’ terms permit them to use content you submit. Direct Moonshot Kimi on the unrestricted tier is one such case: it runs under Moonshot’s own terms and may use submitted content. It is opt-in by name, flagged, and carries a do-not-send warning for personal or regulated data.
Which model providers, and where does inference run?
Per tier, disclosed per model (EU-owned for strict; EU-region; customer-configurable). The catalog’s hosting badge shows the region configured for that model.
Provider data retention
Retention varies by provider and is stated per tier.
Prompt / content storage
Stored in EU Postgres (disk-level encryption at rest; field-level encryption is on the roadmap).

Vulnerability & change management

SDLC / change management
PR review with architect ratification gates, staged deploys, staging-soak discipline, and risk-tiered merges.
Vulnerability scanningIn progress
A runtime-dependency vulnerability CI gate (blocking on high/critical) is in build.
Penetration testingIn progress
Not yet conducted; planned.

Incident response & continuity

Breach notificationPending review
A breach-notification clause is drafted, aligned to the GDPR Art. 33 regulator deadline (72 hours). Customer-notification timing is set out in the DPA.
Incident responseIn progress
Documented and maturing alongside the control-governance program.
Backups
EU backups.
DR / RPO / RTOIn progress
A durable, replayable transport ledger is in build; a formal DR/BCP is in progress. No formal RTO/RPO commitment yet.

Data-subject rights & personnel

Deletion / export / DSARPending review
Data-subject rights are supported — erasure and export paths exist. When you delete content, it is purged from object storage. Text extracted from it, and related metadata, may persist in encrypted database backups until those backups expire — up to 12 months. Backups are not used to restore deleted content, and expiry deletes it permanently.
Personnel securityIn progress
As a small EU company: least-privilege access is in place, and periodic access reviews are being formalized under the control-governance program.

Architecture overview

How it fits together.

A high-level view. Detailed data-flow diagrams and infrastructure specifics are shared under NDA.

  • EU-hosted, multi-tenant with row-level isolation.
  • Per-tier residency routing through a single resolver — the region shown for a tier is the region configured for it.
  • Inference orchestrated through Brain Orchestra.
  • A tamper-evident, signed audit ledger (in progress).

DPA & sub-processors

Who may process your data.

A DPA (GDPR Art. 28) is available on request. Product-specific sub-processors may vary by configuration and agreement.

Sub-processorPurposeRegion
RailwayHosting & infrastructureEU
EvrocEU-owned, Sweden-based inference (eu_strict / eu_sweden)EU
MistralAI inference (EU tiers)EU
AnthropicAI inferencePer route (disclosed per model)
Moonshot / Z.aiAI inference (unrestricted tier — opt-in by name)CN / HK
UmamiPrivacy-conscious analyticsEU
ResendTransactional email (via Amazon SES eu-west-1)EU

Buyer review

Need more for procurement?

We can share a DPA, the sub-processor list, a high-level architecture overview, and the per-leg residency disclosure — plus DPIA inputs and AI-Act classification information on request.