// Our security promise

Sicherheit bei Mindverse

Security is our fundamental promise — not an afterthought. Robust processes keep your data safe, your workspace private, and your information accurate: GDPR-compliant, encrypted, and hosted exclusively in Germany.

GDPR-compliant  ·  DPA under Art. 28  ·  Hosted in Germany  ·  SOC 2 processes

// Audited processes

We implement strict security protocols, verify their effectiveness in regular audits — and disclose our compliance to independent reviewers.

Full details of our data processing are in our privacy policy; our stance on responsible AI in our ethical principles.

// Security architecture

Six pillars that protect your data

From the data center to the vector database: every layer of the platform is designed for confidentiality, integrity, and traceability.

01

Data security

Row-level access controls separate information cleanly by role and organizational unit — everyone sees exactly what they are allowed to see, and nothing more.

02

Vulnerability scans

Regular scans and penetration tests at critical points in the development cycle identify potential weaknesses before they become a risk.

03

GDPR compliance

Secure processing, data processing agreements under Art. 28, and mechanisms to exercise your data-subject rights — from access to erasure.

04

Your data is never used for training

Your content, documents, and prompts are never used to train LLMs. What you enter stays yours.

05

Instance separation

Enterprise customers can get a dedicated LLM instance that is physically and logically isolated from other customer environments.

06

Dedicated prompting and vector database

Prompting methods and the vector database are tailored to your use cases — for precise answers with citations from your own knowledge bases.

// GDPR in detail

GDPR compliance you get in writing

Compliance must not be a marketing word. That is why we answer your data protection officer's questions before they are asked — with a standardized data processing agreement under Art. 28 GDPR and documented processes for every data-subject right.

Requirement Basis How Mindverse delivers
Data processing agreement Art. 28 GDPR Standardized DPA — available on request by email within a very short time.
Right of access Art. 15 GDPR Complete export of your data directly from the platform.
Right to erasure Art. 17 GDPR Documented deletion concepts; complete removal from all systems on request.
Data location Hosting Processing exclusively on servers in certified data centers in Germany.
Sub-processors Transparency Fully documented in our privacy policy — no hidden data flows.
Model training Purpose limitation Your content is never used to train AI models.

// Hosting & sovereign models

Data in Germany — and, if you wish, the AI models too

Mindverse Studio is hosted exclusively in Germany. With our sovereign models such as GPT OSS 120B and DeepSeek V3.2, even inference itself can run on German infrastructure — your data never leaves the EU. And because the platform is LLM-independent, the model choice stays yours: OpenAI, Anthropic, Google, and Mistral via EU endpoints, or fully sovereign.

See how this works company-wide on AI for companies — plans including the sovereign option are on our pricing page.

AES-256 encryption

Encryption in transit (TLS) and at rest — for documents, knowledge bases, and chat histories.

SOC 2 processes

Security and control processes following the SOC 2 framework: documented, verifiable, audit-proof.

Pentests & monitoring

Regular penetration tests, intrusion detection, and continuous monitoring across the entire platform.

RBAC, SSO & audit logs

Role-based access across company, team, and user levels, SSO via OIDC, and complete audit logs.

// Responsible AI

AI that passes the audit

Secure AI does not end at the infrastructure. Prompt injection protection, output filters, and per-team model policies keep AI results under control. As a signatory of the Hamburg Declaration on Responsible AI, we publicly commit to transparent, responsible AI development.

  • Protection against prompt injection and misuse
  • Answers with citations from your knowledge bases
  • Human-in-the-loop approvals in workflows
  • Model policies and permissions per team

Learn how citations work under texts with citations and knowledge bases.

// Proof in practice

Secure AI process automation in action: communications agency media.works saves more than 40% of its time with Mindverse — in full GDPR compliance.

// FAQ

Frequently asked security questions

What security measures does Mindverse use?
Mindverse uses state-of-the-art security protocols, including data encryption, regular security reviews, and strict access controls.
How does Mindverse protect my data?
Your data is stored and processed in encrypted form. We comply with the General Data Protection Regulation (GDPR) and other international standards.
Is Mindverse GDPR-compliant?
Yes, Mindverse is fully GDPR-compliant and meets all legal requirements for data protection.
Is my data shared with third parties?
No, your data is never shared with third parties without your consent. Mindverse offers full transparency in data processing.
Which certifications does Mindverse hold?
Mindverse is ISO 27001 certified and meets international standards for information security management systems.
How does Mindverse secure its AI models?
Our AI models are reviewed regularly to prevent manipulation and ensure safe use.
Are there audits or reviews of the security standards?
Yes, Mindverse conducts regular internal and external security reviews as well as penetration tests.
Is my data deleted after use?
Yes, you have full control over your data. Upon request, we delete your data completely from our systems.
Is the Mindverse platform protected against cyberattacks?
Yes, Mindverse has robust protection against cyberattacks, including firewalls, intrusion detection systems, and continuous monitoring.
How is it ensured that the AI does not process sensitive data?
Our systems use strict filters and protocols to ensure that no sensitive or unauthorized data is processed.

// Start securely

Try the secure, GDPR-compliant AI suite

Boost your productivity without compromising on data protection — free for 7 days, hosted in Germany.

GDPR-COMPLIANT · SERVERS IN GERMANY · SOC 2 PROCESSES