Trust center

Security, privacy & sovereignty

AI.tune is built for data sovereignty – the strongest argument against US platforms. Certified, hosted in Germany, and on request fully within your own infrastructure.

ISO 27001 certifiedGDPR-compliantHosted in GermanyOn-prem availableFunded by the German Federal Ministry (BMFTR)
Secure data handling and hosting in Germany

Hosted in Germany

Your data stays in German data centres – not with US providers.

GDPR-compliant

Data protection under European law, from architecture to operations.

On-prem / local

Fully operable within your own infrastructure on request.

Certifications & funding

Audited security, independently confirmed

ISO/IEC 27001:2022

Certified information security management system (MSECB, certificate no. CERT-001825, valid until 28 May 2029).

View certificate (PDF)

GDPR-compliant

Processing under European data protection law – from architecture to operations.

Funded by the BMFTR

Research and development funding from the German Federal Ministry – an independent quality and innovation signal.

Data & models

Your content stays in the platform and is not used to train third-party models. AI.tune orchestrates the right model for each task.

Hosted in Germany

Operated in German data centres – relevant for regulated industries and public-sector clients.

On-prem / local hosting

Fully operable within your own infrastructure on request – maximum control for sensitive data.

Encryption

Transmission to the current state of the art (SSL/TLS over HTTPS). This site uses local fonts and no tracking cookies.

For IT & integration

Cleanly integrated into your landscape

Single sign-on (SSO)

Connect via SSO/SAML to your identity management – e.g. Microsoft Entra ID / Active Directory.

API & interfaces

Open interfaces for ERP, CRM and custom connections; existing Make, Zapier and n8n workflows via webhook. More on integrations.

SLA & status

Defined availability (99.9 % for private cloud) and a status page for monitoring.

Trust center

Documents & evidence at a glance

Everything procurement, IT and data protection need for a review, in one place. Public or on request.

ISO/IEC 27001:2022 · certificate no. CERT-001825 (MSECB), valid until 28 May 2029
Open certificate →
Data Processing Agreement (DPA), Art. 28 GDPR · standalone agreement, effective on booking
Read online (German) →
Sub-processors · provider, purpose, data location, legal basis
View list →
Privacy policy · cookieless, EU
Open →
Technical & organisational measures (TOMs) · full documentation per Art. 32 GDPR
on request
Penetration test & further audit reports · current external test
on request · NDA
Transparency

Sub-processors in use

Art. 28 GDPR agreements with all; EU SCCs and transfer impact assessments for third-country transfers. As of May 2026.

ProviderPurposeData locationLegal basis
OpenAI Ireland Ltd.AI models (LLM)USA / EUEU SCC
Anthropic PBCAI models (LLM)USAEU SCC
Google Cloud EMEA Ltd.AI models (LLM)USA / EUData Privacy Framework
Hetzner Online GmbHServers, databases, storageGermany / EUArt. 28 GDPR (EU/EEA)
Google LLCWorkspace, emailUSA / EUEU SCC
Development partners (EU)Development & operationsEUArt. 28 GDPR

Contractual guarantee from all AI providers: no use of customer data for model training. Full list incl. addresses on request. Changes are announced at least 30 days in advance per the DPA.

Access to documents

Three tiers, by confidentiality

Public

ISO certificate, DPA, sub-processors, privacy policy. Freely available, no request needed.

On request

Full TOMs documentation, certificate details, eligibility evidence for tenders. By email, informal.

Under NDA

Penetration test report and further internal audit reports. After a short confidentiality agreement.

Request security documents

For tenders we support eligibility and security evidence.

Questions about security?

We discuss your hosting, certification and operations requirements in person – including evidence and on-prem options.

Book a demo