Draft

Trust & Security Center

Your data, your sovereignty.

How Platte protects your data: openly readable in the source code, run on European infrastructure without hyperscalers, documented in this trust center.

Dashed blocks marked “Draft” are text proposals from the AI agent — not yet reviewed. All other content on this page is taken verbatim from the Platte Privacy Report.

This page is a translation. The German version is binding.

As of: 27 August 2026 · Source: Platte Privacy Report

Draft

Open source

Frontend, backend and gateway are open source. Running Platte without Platte is possible.

No hyperscalers

All systems run with European, ISO-certified cloud providers — entirely outside of US corporations.

Dedicated instance

Every customer receives a logically isolated instance. Data and agentic processes stay there.

AES-256 & TLS 1.2/1.3

Encryption at rest and in transit, keys held in a key-management solution.

Draft

Open source

Open source you can verify

Platte pursues a rigorous open-source approach that ensures long-term operational continuity and durably shields customers from the volatility of a young and dynamic AI market. This reduces dependence on individual vendors, increases traceability, and lays a sound foundation for stable, auditable operation over many years.

Draft

Deployment

European infrastructure, dedicated instance

All Platte systems run with European, ISO-certified cloud providers. Platte entirely forgoes the offerings of hyperscalers in order to guarantee full independence from outside the EU and to counter geopolitical risks.

Every Platte customer receives a dedicated, logically isolated instance in which data is stored and agentic processes are executed. In addition, all AI inference and web requests are aggregated through the Platte Privacy Gateway, which makes tracing individual requests considerably harder.

Besides the standard deployment in the Platte Managed Cloud, the isolated instance can also be hosted directly at the customer (self-hosting or managed service), which makes integrating local network services possible. Connecting dedicated or local AI inference servers is likewise possible.

Diagram: three customer instances send their requests through the Platte Privacy Gateway to two EU LLM providers and to web search and web crawling.

Draft

Transparency

Sub-processors at a glance

NameLocationService
Scaleway SASParis, France, EUHosting, LLM inference
TensorX Ltd.Dublin, Ireland, EUHelsinki, Finland, EULLM inference

Draft

Controls

Our security controls in detail

Application & Interface Security

  • Are secure software development lifecycle practices (SSDLC) applied to the design, development, deployment and operation of the application?Yes

    Platte follows secure development practices, including code reviews, automated and manual testing before release, and a defined change management process.

  • Is application security tested automatically as part of the development process?Yes

    Manual and automated security testing and code reviews are performed for every release, supported by static analysis and AI-assisted analysis.

  • Are programming interfaces (APIs) developed, deployed and operated in line with leading security practices?Yes

    All interfaces are thoroughly examined for vulnerabilities and are protected by security mechanisms that meet industry standards

  • Are application security risks formally assessed and remediated?Yes

    Security risks are assessed during the development process. Identified vulnerabilities are prioritised and remediated before release.

Audit Assurance & Compliance

  • Are independent audit assurance and compliance assessments performed at least annually?Not yet

    Internal reviews are carried out regularly. External audits are planned.

  • Are risk-based corrective actions from audit findings tracked through to completion?Yes

    Findings from internal reviews are tracked and addressed. Issues reported by customers are logged, prioritised and resolved.

Business Continuity

  • Is a business continuity plan established, documented and maintained?Yes

    Platte maintains a Business Continuity & Disaster Recovery plan covering critical business operations, continuity of the website/sales and customer support.

  • Are business continuity plans tested at planned intervals?Yes

    Business continuity procedures, including backup restoration and failover processes, are tested regularly.

  • Are redundant systems and backups maintained for critical business operations?Yes

    All critical systems and backups are operated redundantly

Change Control & Configuration

  • Are change management policies and procedures established and followed?Yes

    All software changes follow a defined process, including development, code review, testing and staged rollout.

  • Is a risk assessment performed before proposed changes are deployed?Yes

    Changes are reviewed for potential impact on security, stability and compatibility before release.

  • Are configuration management practices applied to ensure consistent and secure system states?Yes

    Build configurations are stored in version control. Release builds follow a defined, repeatable process.

Cryptography & Encryption

  • Are cryptographic controls defined and implemented to protect data?Yes

    Encryption for data in transit (TLS/SSL) and at rest (AES-256)

  • Are procedures established for managing encryption keys?Yes

    Encryption keys are stored securely in a key-management solution that meets the current state of the art

  • Are cryptographic algorithms and protocols used that follow industry standards?Yes

    Uses AES-256 for file encryption, TLS 1.2/1.3 for secure connections, and SHA-256 or stronger for integrity checks.

Datacenter Security

  • Are physical security perimeters and controls implemented to protect datacenter facilities?Yes

    Platte operates no datacenters; our partners’ datacenters are protected to the most modern security standards

Data Security & Privacy

  • Are data classification and data handling policies established?Yes

    Platte maintains policies for classifying and handling internal company data as well as customer data, protected by appropriate access controls. The principle of data minimisation is applied.

  • Are privacy policies aligned with applicable regulations (e.g. GDPR, CCPA)?Yes

    A published privacy policy is maintained in compliance with the applicable regulations.

  • Are there procedures for secure data disposal?Yes

    Platte offers secure file deletion features to customers. Internal business data follows secure disposal practices.

  • Are data retention policies defined and enforced?Yes

    Defined retention periods are observed for support records, customer details and business documents.

  • Is personal data processed in accordance with legal requirements?Yes

    Personal data is processed in accordance with the GDPR and applicable local regulations. Documented processes exist for legal bases, purpose limitation and data minimisation. Data processing agreements (DPAs) are concluded with customers; appropriate technical and organisational measures (including access controls, encryption and logging) are implemented.

Governance, Risk & Compliance

  • Is an information security management system established?Yes

    Platte maintains an information security policy defining its approach to protecting assets and to risk management.

  • Are roles and responsibilities for information security defined and assigned?Yes

    Security responsibilities are defined in the corporate policies and are overseen at management level.

  • Is a risk management process implemented to identify, assess and treat risks?Yes

    Risks are identified and assessed in the course of ongoing operations and development planning.

  • Are applicable legal, regulatory and contractual requirements identified and documented?Yes

    Platte monitors requirements such as the GDPR and the EU Cyber Resilience Act.

Human Resources Security

  • Are background checks performed on employees and contractors?Yes

    New personnel with access to sensitive systems or data undergo an appropriate vetting check. All software suppliers and service providers are also thoroughly vetted before contracts are signed.

  • Are all employees offered security awareness training?Yes

    The team keeps its knowledge of security threats and secure coding practices current. New findings are shared within the team on a regular basis.

  • Are access rights revoked when employment ends?Yes

    Procedures exist to withdraw access to all systems and repositories upon departure.

Identity & Access Management

  • Is a formal user access management process implemented?Yes

    Access to development systems, source code and infrastructure is restricted to authorised personnel (need-to-know principle).

  • Is multi-factor authentication (MFA) enforced for access to critical systems?Yes

    MFA is enabled for critical systems such as source code repositories and cloud hosting accounts.

  • Are access rights reviewed regularly?Yes

    Access rights are reviewed regularly and on personnel changes. The principle of least privilege is applied.

  • Are unique user identifiers assigned and the use of shared accounts prohibited?Yes

    All employees have unique credentials; the use of shared accounts is avoided.

Infrastructure & Virtualisation

  • Are network security controls implemented to protect the infrastructure environment?Yes

    Platte deploys network security controls to protect its (production and development) environments, including network segmentation, restrictive firewall rules (default-deny), hardened remote access (e.g. VPN/SSO), and logging and monitoring of security-relevant events.

  • Is the network architecture designed with appropriate segmentation and security zones?Yes

    The network architecture is designed around a minimal attack surface and uses segmentation/security zones (e.g. separating publicly reachable components, internal services and administrative access). Access is restrictively governed.

Logging & Monitoring

  • Are logging and monitoring functions implemented for critical systems and security events?Yes

    Logging is enabled on development systems and the web infrastructure.

  • Are logs reviewed and retained for an appropriate period?Yes

    System and access logs are retained for an appropriate period and reviewed for anomalies.

Draft

Documents

Documents and contact

Draft

The legal foundations for running Platte are here:

Draft

We will add these control domains to this trust center as soon as their documentation is complete:

  • Security Incident Management
  • Supply Chain Management
  • Threat & Vulnerability Management
  • Endpoint Management

Our data protection contact answers questions about privacy and security:

Responsible for data protection

Platte UG (haftungsbeschränkt) i.G.
Am Krögel 2
10179 Berlin
Germany

Email: lucas@platte.ai

Contact for data protection matters: Friedrich Theodor Gies