Security & compliance · written for your DPO and CTO

EU data.
EU compute.
EU team.

Frankfurt + Vienna primary. Schrems II compliant. No US sub-processors for production data. Your DPO gets the full memo before signing — and disagrees with us less often than they expect to.

Four pillars

Four non-negotiables
that predate every project.

If a project requires breaking one, we don't take it. Read these as filters, not marketing.

Pillar 01 · Sovereignty

Your data never leaves EU soil.

Production data stays in Frankfurt (primary) or Vienna (DR). Open-weight models on EU GPU clusters. Schrems II compliant — written memos available pre-signing for your legal review.

  • Hetzner Germany + Interxion Austria · ISO 27001
  • No US sub-processors for production data, ever
  • EU-resident team only · no offshore subcontractors
  • Sub-processor list published, change notice clauses in every DPA
Pillar 02 · Ownership

You own every line of code.

Source repository in your GitHub or GitLab from commit one. Models, prompts, configs — assigned to you on delivery under your standard internal-use licence.

  • Code in your repo · day 1 · not "after final payment"
  • Open-weight models where the workload allows
  • No API lock-in to Apexa-hosted services
  • Fork-out plan in every SoW · documented exit path
Pillar 03 · Compliance

EU AI Act, by default.

Every project gets a written EU AI Act risk classification before scope is finalised. Limited-risk and high-risk projects get the full documentation pack: data lineage, model cards, governance plan.

  • EU AI Act risk class memo per project · pre-build
  • Model cards, data cards, lineage docs · in your repo
  • GDPR DPA, DPIA template, ROPA inputs · always
  • Head of Compliance reviews every SoW
Pillar 04 · Posture

Built like infrastructure, not a pilot.

Auth, audit logs, encryption-at-rest, encryption-in-transit, secrets management, role-based access, observability — these are week-1 requirements, not week-12 surprises. We won't ship a service without them.

  • Secrets in Vault / your KMS · never in env files
  • TLS 1.3 in transit · AES-256 at rest · always
  • Full audit logs · structured · shipped to your SIEM
  • Penetration test before every production go-live
Architecture

Where everything lives.

A reference architecture. Per-project specifics differ, but the location columns rarely move — and when they do, it's documented before signing.

Source code
Git repo

Application code, infrastructure-as-code, model configs, prompts, documentation. Every commit, from day one.

Your GitHub / GitLab
Production data
PII, business data

All data your system reads or writes — customer records, transactions, internal documents, embeddings.

Frankfurt / Vienna
Inference
Model serving

Open-weight LLMs and traditional ML models running on EU GPU infrastructure. Your prompts and completions never leave the EU.

EU GPU cluster
Vector store
Embeddings, RAG

Document embeddings, retrieval indices. Co-located with the data they index — never replicated outside the EU.

Frankfurt / Vienna
Logs & observability
Audit, traces, metrics

Structured audit logs, request traces, metrics. Shipped to your SIEM (Splunk, Elastic, Sentinel) — we don't keep production logs.

Your SIEM
Secrets & keys
Auth credentials

API keys, certificates, signing keys. In your KMS or a Vault instance you control. We never store production credentials.

Your KMS / Vault
Identity & SSO
User auth

Authentication via your existing IdP (Entra, Okta, Keycloak). No Apexa-managed user database. SCIM provisioning where needed.

Your IdP
Data flow

A request, traced.

A single inference request, from your user clicking the button to the response landing back in your UI. Five hops. Every hop inside EU borders. Every hop logged.

Step 01

User action

Your employee clicks "Generate draft" in your application. Authenticated via your IdP.

YOUR IDP
Step 02

API gateway

Request hits the gateway in Frankfurt. Audit log entry written. Auth token validated against your IdP.

FRANKFURT
Step 03

Retrieval

Vector store queried for relevant context from your document corpus. Indices co-located with source data.

FRANKFURT
Step 04

Inference

Open-weight model on EU GPU cluster generates response. Prompt and completion logged to your audit log.

EU GPU
Step 05

Return

Response delivered to user. Full trace shipped to your SIEM. Total round-trip: typically under 4 seconds.

YOUR SIEM

Zero hops outside EU jurisdiction. Zero data sent to US-controlled APIs. Zero exceptions.

Compliance

Frameworks & status.

Where we stand against the frameworks that matter to mid-market European buyers. Honest current state, not aspirational logos.

GDPR
EU 2016/679
Standard DPA in every engagement. ROPA inputs delivered. DPIA template provided. We are processor; you are controller.
✓ Operating
EU AI Act
Reg. 2024/1689
Risk classification memo per project. Documentation pack for limited-risk and high-risk systems. Klaudia (Head of Compliance) leads.
✓ Operating
Schrems II
CJEU C-311/18
No transfers to US-controlled services for production data. Memo per project documenting transfer mechanisms (or absence thereof).
✓ Operating
ISO 27001
ISMS
Our hosting providers (Hetzner, Interxion) are certified. Apexa's own ISMS audit in progress.
→ in progress
SOC 2 Type II
For US-headquartered clients
Optional · scoped per client. We deliver SOC 2 evidence packs through our auditor when required by US-parented buyers.
→ On request
DORA
EU 2022/2554
Relevant for our financial-services clients. Sub-processor register, exit plans, ICT risk documentation included for FS engagements.
✓ For FS clients
NIS2
EU 2022/2555
Relevant for clients in regulated sectors (energy, transport, manufacturing). Incident response runbooks aligned to NIS2 reporting.
✓ Operating
DPO FAQ

Questions your DPO
asks first.

If yours isn't listed, send us a question — we'll answer in writing within one working day.

Where is data physically stored, and on whose hardware?+
Hetzner (Nuremberg, Germany) and Interxion (Vienna, Austria). Both ISO 27001 certified, both EU-incorporated, both not subject to US CLOUD Act or FISA 702. Hardware is dedicated, not shared. We can switch to your own tenancy on AWS Frankfurt, Azure West Europe, or your on-prem if required.
Which sub-processors do you use, and where are they?+
Production data path: Hetzner (DE), Interxion (AT), and EU-incorporated GPU providers. Non-production: GitHub for source (you control your tenancy), Stripe EU for billing (no production data). No US sub-processors for production data. The full sub-processor list is in the DPA, with 30-day change notification.
What about Schrems II — are there any EU→US transfers at all?+
For production data, no. For corporate operations (e.g. our own email), we use EU-region Microsoft 365 with the EU Data Boundary. Schrems II memo per project documents zero production-path transfers; non-production transfers (if any) are listed with the relevant transfer mechanism.
Can data be processed on our own tenancy / VPC / on-prem?+
Yes — at any of the three layers. We can deploy: (a) on Apexa-managed EU infrastructure, (b) on your cloud tenancy (AWS Frankfurt, Azure West Europe, GCP Frankfurt), or (c) fully on-premises. Roughly 40% of our clients choose option (b) or (c). Pricing is identical.
Which models do you use, and do they train on our data?+
Default: open-weight models (Llama 3 family, Mistral, Qwen) on EU GPU infrastructure. No training on your data by any third party — we run inference only. If a closed-API model is the right fit (rare), we use the EU-region endpoints with no-training contractual terms, documented per project.
How do we exit if we want to stop working with Apexa?+
Every SoW contains a fork-out plan. The code is in your repo from day one. The infrastructure-as-code lets your team or another vendor stand up the system in your tenancy without our involvement. We hand over: documentation, runbooks, training, and 30 days of email support post-handover. No data hostage scenarios are possible because we never hold production data on Apexa-controlled storage you can't access.
What happens if Apexa goes out of business?+
Code is in your repos. Models and configs are in your repos. Infrastructure runs on accounts you own (option b/c) or has a documented migration path (option a). The escrow is automatic — it's the architecture, not a legal mechanism. Worst-case rebuild from your repos: a competent senior engineer, two weeks.
How long until we can talk to a real person about specifics?+
If your question is in writing, less than one working day. If you want a 20-minute live conversation with our Head of Compliance, book the Clarity Call and tell us in the booking form that you want Klaudia on the call. We'll add her — no upcharge, no separate "security review call" funnel.

Bring your DPO to the call.

We'll add Klaudia, our Head of Compliance. No upcharge, no separate funnel.

Book your Clarity Call