Trust center

Security, privacy and AI governance for less vendor-dependent operations.

Xalerate helps organizations move from AI experiments to operational use while avoiding the one-vendor trap. This page explains the controls, practices and limits behind that promise, without presenting certifications or compliance outcomes that are not yet in place.

Welcome to the Xalerate Trust Center.

Xalerate builds software for AI operations: model routing, governed memory, agent control, audit evidence and usage insight. The mission is practical resilience for organizations and Europe: more AI, less vendor dependency and choices that can still be changed over time.

Xalerate is designed as an independent control layer between the organization and the AI vendor landscape. Trust for this category is practical: buyers need to know what is controlled, what is logged, who may process data, how provider optionality works and which claims are not being made.

This page is the public starting point. Product-specific security review, architecture details and commercial data-processing terms are handled with qualified buyers under the right agreement.

Control areas

What Xalerate is designed to control.

The product suite is built around AI operational controls: model choice, governed memory, agent oversight, audit evidence, usage visibility and reduced dependency on any single vendor stack.

Models

Routing and provider optionality.

Brain Orchestra is the model-routing layer for policy-based provider choice, territorial requirements, audit visibility, cost control and reversibility away from a single model provider.

Knowledge

Governed memory and context.

Nootio structures knowledge, rules and memory so teams and agents can reuse context with access control and traceability.

Agents

Agent sprawl, ownership and budgets.

Fleet Tower is positioned as the control tower for agent ownership, tool access, budgets, approval points and operational visibility.

Evidence

Records of AI activity.

Xalerate Veris is the audit-evidence product for actor identity, model choice, context, approvals, costs and decision traces.

Usage

Visibility into adoption and spend.

Xalerate Insights is the usage and governance signal layer for adoption, cost, provider exposure and dependency risk.

Enterprise

Packaged through Xalerate Polhem.

Xalerate Polhem packages the same capabilities for larger organizations with governance, integration and partner-delivery needs.

Resources

Start here for buyer review.

The public page keeps the first pass open. Deeper documents are shared when the product, use case and review scope are clear.

Privacy posture

Website privacy information, analytics posture, assistant processing and data subject contact path.

Read summary

Legal notice

Product availability limits by category, public-copy disclaimers and customer responsibility boundaries.

Read notice

Security questionnaire

Our security and privacy posture — data residency, encryption, access control, audit, AI data handling and sub-processors.

View security posture

Architecture overview

High-level product architecture can be shared for the relevant product or Xalerate Polhem module.

Request overview

DPA and subprocessors

Commercial data-processing terms and product-specific subprocessors are handled through the relevant agreement.

Request details

Product availability

Live, waitlist, internal-beta and planned products have different availability, support and agreement requirements.

View availability

Security and privacy

Current public posture.

This is the information Xalerate can state publicly today. More detailed security information can be shared during qualified enterprise conversations.

Security practices

  • Security headers are set on the Xalerate site, including CSP, HSTS, Referrer-Policy and X-Content-Type-Options.
  • Brain Orchestra is designed for model policy, actor attribution, routing and audit visibility.
  • Secrets are expected to be configured through Railway environment variables, not committed to source.

Privacy practices

  • Xalerate AB is the data controller for the public website.
  • Email enquiries are processed so Xalerate can respond.
  • If enabled, the website assistant processes messages through Brain Orchestra and configured downstream model providers.

Compliance posture

Clear claims, no shortcuts.

Xalerate provides technical controls and evidence that can support governance work. Customers remain responsible for their own legal obligations, AI-system classification and deployment validation.

AreaPublic positionStatus
GDPRPrivacy-aware product and website postureXalerate summarises its website privacy posture on this Trust Center and uses controlled processing descriptions for the website and assistant. A DPA is being prepared with counsel and is available on request.Summary published
EU-friendly deploymentDeployment and routing choicesProduct and enterprise deployment options may support EU-friendly architectures, subject to configuration and agreement.Configuration-dependent
Sovereignty-enabling controlsModel choice and portabilityXalerate can support sovereignty goals through model choice, routing policy, portable memory, audit evidence and EU-friendly deployment options, subject to configuration and agreement.Configuration-dependent
SOC 2 / ISO 27001External certificationsXalerate does not currently present public SOC 2 or ISO 27001 certification claims on this site.Not claimed
AI Act and sector rulesCustomer use-case obligationsXalerate can provide controls and evidence, but customers classify and validate their own AI use cases.Customer-specific

Subprocessors and data flow

Who may process website data.

This page covers the public Xalerate website. Product-specific subprocessors and deployment details may vary by product, customer agreement and configuration.

ProviderRoleNotes
RailwayHostingHosts the public Xalerate site.Used for website delivery and server runtime.
UmamiPrivacy-conscious analyticsMay be used for anonymous page-view analytics without cookies or third-party tracking.Used only if enabled on the deployed site.

Updates

Current trust-center status.

The Trust Center is versioned with the public website. Material changes to product availability, processors or review documents should be reflected here.

Current

Published Trust Center

Initial public Trust Center published for staging review on June 22, 2026.

Mixed

Product availability

Nootio is live. Brain Orchestra and Just Smarter Eval are waitlist — sign-up is gated behind an invite. Fleet Tower and Xalerate Chat are in internal beta — in use inside Xalerate, not yet with external customers. Xalerate Insights and Xalerate Veris are planned.

On request

Buyer review access

Security questionnaires, architecture overviews and DPA details are handled during qualified buyer or partner conversations.

Get in touch

Need a security or privacy review?

Contact Xalerate with the product, use case and review scope. We can route the conversation to the right product, enterprise platform or partner-delivery track.