// Our security promise
Sicherheit bei Mindverse
Security is our fundamental promise — not an afterthought. Robust processes keep your data safe, your workspace private, and your information accurate: GDPR-compliant, encrypted, and hosted exclusively in Germany.
GDPR-compliant · DPA under Art. 28 · Hosted in Germany · SOC 2 processes
// Audited processes
We implement strict security protocols, verify their effectiveness in regular audits — and disclose our compliance to independent reviewers.
Full details of our data processing are in our privacy policy; our stance on responsible AI in our ethical principles.
// Security architecture
Six pillars that protect your data
From the data center to the vector database: every layer of the platform is designed for confidentiality, integrity, and traceability.
Data security
Row-level access controls separate information cleanly by role and organizational unit — everyone sees exactly what they are allowed to see, and nothing more.
Vulnerability scans
Regular scans and penetration tests at critical points in the development cycle identify potential weaknesses before they become a risk.
GDPR compliance
Secure processing, data processing agreements under Art. 28, and mechanisms to exercise your data-subject rights — from access to erasure.
Your data is never used for training
Your content, documents, and prompts are never used to train LLMs. What you enter stays yours.
Instance separation
Enterprise customers can get a dedicated LLM instance that is physically and logically isolated from other customer environments.
Dedicated prompting and vector database
Prompting methods and the vector database are tailored to your use cases — for precise answers with citations from your own knowledge bases.
// GDPR in detail
GDPR compliance you get in writing
Compliance must not be a marketing word. That is why we answer your data protection officer's questions before they are asked — with a standardized data processing agreement under Art. 28 GDPR and documented processes for every data-subject right.
| Requirement | Basis | How Mindverse delivers |
|---|---|---|
| Data processing agreement | Art. 28 GDPR | Standardized DPA — available on request by email within a very short time. |
| Right of access | Art. 15 GDPR | Complete export of your data directly from the platform. |
| Right to erasure | Art. 17 GDPR | Documented deletion concepts; complete removal from all systems on request. |
| Data location | Hosting | Processing exclusively on servers in certified data centers in Germany. |
| Sub-processors | Transparency | Fully documented in our privacy policy — no hidden data flows. |
| Model training | Purpose limitation | Your content is never used to train AI models. |
// Hosting & sovereign models
Data in Germany — and, if you wish, the AI models too
Mindverse Studio is hosted exclusively in Germany. With our sovereign models such as GPT OSS 120B and DeepSeek V3.2, even inference itself can run on German infrastructure — your data never leaves the EU. And because the platform is LLM-independent, the model choice stays yours: OpenAI, Anthropic, Google, and Mistral via EU endpoints, or fully sovereign.
See how this works company-wide on AI for companies — plans including the sovereign option are on our pricing page.
AES-256 encryption
Encryption in transit (TLS) and at rest — for documents, knowledge bases, and chat histories.
SOC 2 processes
Security and control processes following the SOC 2 framework: documented, verifiable, audit-proof.
Pentests & monitoring
Regular penetration tests, intrusion detection, and continuous monitoring across the entire platform.
RBAC, SSO & audit logs
Role-based access across company, team, and user levels, SSO via OIDC, and complete audit logs.
// Responsible AI
AI that passes the audit
Secure AI does not end at the infrastructure. Prompt injection protection, output filters, and per-team model policies keep AI results under control. As a signatory of the Hamburg Declaration on Responsible AI, we publicly commit to transparent, responsible AI development.
- Protection against prompt injection and misuse
- Answers with citations from your knowledge bases
- Human-in-the-loop approvals in workflows
- Model policies and permissions per team
Learn how citations work under texts with citations and knowledge bases.
// Proof in practice
Secure AI process automation in action: communications agency media.works saves more than 40% of its time with Mindverse — in full GDPR compliance.
// FAQ
Frequently asked security questions
What security measures does Mindverse use?
How does Mindverse protect my data?
Is Mindverse GDPR-compliant?
Is my data shared with third parties?
Which certifications does Mindverse hold?
How does Mindverse secure its AI models?
Are there audits or reviews of the security standards?
Is my data deleted after use?
Is the Mindverse platform protected against cyberattacks?
How is it ensured that the AI does not process sensitive data?
// Start securely
Try the secure, GDPR-compliant AI suite
Boost your productivity without compromising on data protection — free for 7 days, hosted in Germany.
GDPR-COMPLIANT · SERVERS IN GERMANY · SOC 2 PROCESSES