ISO/IEC 27001:2022
How we safeguard the security and privacy of your data
Artific is the AI platform that helps your organisation speed up, improve and simplify its processes. A secure, controllable environment for putting AI to work smartly and with purpose.
Built by Dutch AI professionals, hosted on Dutch soil, with privacy and security as the starting point. Below you can read exactly how that works.
- GDPR-proof and hosted in the Netherlands
- ISO 27001 certified
- Independent of language models and tools
Starting point
Privacy by designand privacy by default.
Our software is developed according to the principles of privacy by design and privacy by default. User settings protect privacy out of the box, and privacy risks are assessed at every stage of development. So security is not a layer added on top later: it is the shape the platform is built in.
- Certification
- ISO 27001
- Audited by LMS Assessments Limited
- Hosting
- Within the EU
- On Dutch soil
- Encryption
- AES-256
- In transit and at rest
Where your data goes
Artific has developed its own AI platform. Within it, the AI Engine is the foundation of our AI solutions. To work properly, data is stored in file storage and a vector database. The engine uses AI models developed by third parties: embeddings, image generation and Large Language Models. What that means for your data is set out below, layer by layer.
Data security
You own your data.We secure it.
Four measures that apply to every environment we manage, from the first time you add a document to last night’s backup.
You own your data
Our customers own and manage their own data within our software and decide for themselves who has access to it. Because we can access that environment for maintenance and updates, we sign a data processing agreement with every customer.
Encrypted in transit and at rest
All data sent to the platform is encrypted, so the information is unreadable if third parties look in or intercept it. That applies to what administrators enter in the back end and to what end users send during a conversation with an assistant. Our databases also use encryption at rest, with AES-256.
Secure storage
Customer data is kept in secure, encrypted databases that can only be accessed with a separate access code. Those codes, and the access codes for API connections between systems, are available only to the developers responsible for development and maintenance.
Automatic backups
We regularly make automated backups of all data, so nothing is lost in an outage, a breach or a cyberattack. Those backups are stored securely.
Want to see what that data processing agreement says beforehand?
Access management
Nobody gets inunless you decide they can.
Access to the application
Access to our applications requires authentication. For this we use Firebase Authentication, an established solution from Google Firebase that has been extensively tested and complies with ISO 27001, ISO 27017, ISO 27018, SOC 1, SOC 2 and SOC 3.
Access is based on email address and password and integrates with major software providers such as Google and Microsoft. That connection is used solely to identify users. No personal data is shared with them.
All passwords are stored encrypted. That means we have no access to users’ passwords and cannot view them or retrieve them for a user. We can reset a password, so that the user sets a new one themselves. Within the application, permission management lets you decide what level of access each user has.
Access to the codebase
Access to the codebase, meaning the source code of the applications, is strictly limited. Only Artific employees can view or change the code, and they do so through personal user accounts.
That prevents unauthorised access and ensures transparency: every change can be traced back to the employee who made it.
Access codes for API connections between systems are handled in the same way as access to customer data. They are available only to the developers responsible for developing and maintaining the systems.
Hosting
Our serversor yours.
The platform can run in two ways, and they divide the responsibility differently. That is why they sit side by side here, instead of the second one disappearing into the small print.
Hosted by Artific
Our software runs on secure, ISO 27001 certified servers in the Netherlands, within the EU. Data is protected with encryption and access management, and the software takes the latest technological standards into account.
On your own server
As a customer, you can choose to run our software on your own dedicated server. You are then responsible for securing that environment and for managing access to it. Data is protected with encryption there too.
Use of language models
A language model gets fragments,never your whole file.
We use third parties to run models, which means information is shared with those third parties. The data that is shared is cut into small pieces, known as chunks, so that no context can be attached to it. That also means a model cannot use those small pieces to store anything.
As a fallback, those small pieces are not stored at all, and the language model also strips the personal data out of them.
OpenAI
The integration runs through OpenAI’s Python software development kit, called from the LangChain framework. This data is not used for training purposes.
Vertex AI, part of Google Cloud Platform
The interaction runs through the Python software development kit that Google provides. Both OpenAI and Vertex AI are GDPR-compliant.
Frequently asked questions
Short answersto the questions we hear most.
Where is my data stored?
By default, on secure, ISO 27001 certified servers in the Netherlands, within the EU. If you choose to run our software on your own dedicated server, the data is stored there and you are responsible for the security and access management of that environment.
How does Artific make sure it complies with the GDPR?
Our software is developed according to privacy by design and privacy by default: user settings protect privacy out of the box and privacy risks are assessed at every stage of development. You remain the owner of your data and decide who has access to it, we sign a data processing agreement with every customer, and the language models we use are GDPR-compliant and do not use your data for training.
How is access to my data secured?
Access to our applications requires authentication through Firebase Authentication, based on email address and password. Passwords are stored encrypted, so we cannot view or retrieve them; all we can do is start a reset. Within the application, permission management lets you decide what level of access each user has. The underlying databases can only be accessed with a separate access code, which is available only to the developers who maintain the system.
Is my data encrypted?
Yes, both in transit and at rest. Everything sent to the platform is encrypted, so it is unreadable if third parties intercept it. Our databases also use encryption at rest with AES-256, meaning a 256-bit key, so the data is stored encrypted on disk as well.
What is data chunking and why is it secure?
Before any data goes to a language model, we cut it into small pieces: chunks. A single chunk on its own carries no context, so a model cannot use it to store anything about your organisation. As an extra fallback, those chunks are not stored at all and the model also strips the personal data out of them.
Can I see for myself what happens to my data?
Yes. You own and manage your data within our software and use permission management to decide who has access to it. What we, as the processor, may do with that data is set out in the data processing agreement we sign with every customer.
Does Artific work with a data processing agreement?
Yes. Because we have access to your environment for maintenance and updates, we sign a data processing agreement with every customer. It sets out which data we process, for what purpose, and which arrangements apply. Ask us for the draft if you want to review it beforehand.
A question about your own situation?
Every organisation has its own requirements: a security officer with a questionnaire, a DPIA that needs completing, or an IT department that wants to know where everything is. Put it to us and we will go through it together.