EU data.
EU compute.
EU team.
Frankfurt + Vienna primary. Schrems II compliant. No US sub-processors for production data. Your DPO gets the full memo before signing — and disagrees with us less often than they expect to.
Four non-negotiables
that predate every project.
If a project requires breaking one, we don't take it. Read these as filters, not marketing.
Your data never leaves EU soil.
Production data stays in Frankfurt (primary) or Vienna (DR). Open-weight models on EU GPU clusters. Schrems II compliant — written memos available pre-signing for your legal review.
- ✓Hetzner Germany + Interxion Austria · ISO 27001
- ✓No US sub-processors for production data, ever
- ✓EU-resident team only · no offshore subcontractors
- ✓Sub-processor list published, change notice clauses in every DPA
You own every line of code.
Source repository in your GitHub or GitLab from commit one. Models, prompts, configs — assigned to you on delivery under your standard internal-use licence.
- ✓Code in your repo · day 1 · not "after final payment"
- ✓Open-weight models where the workload allows
- ✓No API lock-in to Apexa-hosted services
- ✓Fork-out plan in every SoW · documented exit path
EU AI Act, by default.
Every project gets a written EU AI Act risk classification before scope is finalised. Limited-risk and high-risk projects get the full documentation pack: data lineage, model cards, governance plan.
- ✓EU AI Act risk class memo per project · pre-build
- ✓Model cards, data cards, lineage docs · in your repo
- ✓GDPR DPA, DPIA template, ROPA inputs · always
- ✓Head of Compliance reviews every SoW
Built like infrastructure, not a pilot.
Auth, audit logs, encryption-at-rest, encryption-in-transit, secrets management, role-based access, observability — these are week-1 requirements, not week-12 surprises. We won't ship a service without them.
- ✓Secrets in Vault / your KMS · never in env files
- ✓TLS 1.3 in transit · AES-256 at rest · always
- ✓Full audit logs · structured · shipped to your SIEM
- ✓Penetration test before every production go-live
Where everything lives.
A reference architecture. Per-project specifics differ, but the location columns rarely move — and when they do, it's documented before signing.
Application code, infrastructure-as-code, model configs, prompts, documentation. Every commit, from day one.
All data your system reads or writes — customer records, transactions, internal documents, embeddings.
Open-weight LLMs and traditional ML models running on EU GPU infrastructure. Your prompts and completions never leave the EU.
Document embeddings, retrieval indices. Co-located with the data they index — never replicated outside the EU.
Structured audit logs, request traces, metrics. Shipped to your SIEM (Splunk, Elastic, Sentinel) — we don't keep production logs.
API keys, certificates, signing keys. In your KMS or a Vault instance you control. We never store production credentials.
Authentication via your existing IdP (Entra, Okta, Keycloak). No Apexa-managed user database. SCIM provisioning where needed.
A request, traced.
A single inference request, from your user clicking the button to the response landing back in your UI. Five hops. Every hop inside EU borders. Every hop logged.
User action
Your employee clicks "Generate draft" in your application. Authenticated via your IdP.
YOUR IDPAPI gateway
Request hits the gateway in Frankfurt. Audit log entry written. Auth token validated against your IdP.
FRANKFURTRetrieval
Vector store queried for relevant context from your document corpus. Indices co-located with source data.
FRANKFURTInference
Open-weight model on EU GPU cluster generates response. Prompt and completion logged to your audit log.
EU GPUReturn
Response delivered to user. Full trace shipped to your SIEM. Total round-trip: typically under 4 seconds.
YOUR SIEMZero hops outside EU jurisdiction. Zero data sent to US-controlled APIs. Zero exceptions.
Frameworks & status.
Where we stand against the frameworks that matter to mid-market European buyers. Honest current state, not aspirational logos.
Questions your DPO
asks first.
If yours isn't listed, send us a question — we'll answer in writing within one working day.
Where is data physically stored, and on whose hardware?+
Which sub-processors do you use, and where are they?+
What about Schrems II — are there any EU→US transfers at all?+
Can data be processed on our own tenancy / VPC / on-prem?+
Which models do you use, and do they train on our data?+
How do we exit if we want to stop working with Apexa?+
What happens if Apexa goes out of business?+
How long until we can talk to a real person about specifics?+
Bring your DPO to the call.
We'll add Klaudia, our Head of Compliance. No upcharge, no separate funnel.
Book your Clarity Call →
