EN
FrançaisEnglishDeutschEspañolItalianoNederlands
Security by verifiable controls

Local deployment is a starting point, not the complete security answer

Security depends on architecture, accounts, permissions, updates, logs and operating discipline.

Direct answer

GriotAI limits the scope of data and connectors, uses dedicated accounts where possible, keeps retrieval aligned with user rights and requires approval for sensitive actions. The exact guarantees depend on the deployed configuration and must be verified in the customer's environment.

Controls to verify

Data location

Document where originals, working copies, indexes, models, logs and backups are stored.

Identity and permissions

Use named accounts, least privilege, periodic access reviews and multi-factor authentication where available.

Network flows

List remote services, destinations and telemetry instead of relying on the word local.

Operations

Monitor availability, vulnerabilities, updates, failed actions and backup restoration.

Human control remains necessary

A draft can be produced automatically while sending, deleting, ordering or changing a record remains gated. The level of approval should reflect the business impact and reversibility of the operation.

Logs must help investigate an incident without collecting unnecessary personal data. Retention periods and access to those logs must be defined.

Security questions for a supplier

Frequently asked questions

Does local AI automatically comply with GDPR?

No. Purpose, legal basis, minimisation, access, retention, information, security and processor relationships still need to be assessed.

Can cloud connectors still be used?

Yes, when their purpose, permissions and data flows are understood and accepted. Local inference does not make a remote connector local.

Continue exploring

Start with one measurable process

Choose one use case, a controlled document set and a result that your team can verify.

Request a demo