Draft
Trust & Security Center
Your data, your sovereignty.
How Platte protects your data: openly readable in the source code, run on European infrastructure without hyperscalers, documented in this trust center.
Dashed blocks marked “Draft” are text proposals from the AI agent — not yet reviewed. All other content on this page is taken verbatim from the Platte Privacy Report.
This page is a translation. The German version is binding.
Draft
Open source
Frontend, backend and gateway are open source. Running Platte without Platte is possible.
No hyperscalers
All systems run with European, ISO-certified cloud providers — entirely outside of US corporations.
Dedicated instance
Every customer receives a logically isolated instance. Data and agentic processes stay there.
AES-256 & TLS 1.2/1.3
Encryption at rest and in transit, keys held in a key-management solution.
Draft
Open source
Open source you can verify
Platte pursues a rigorous open-source approach that ensures long-term operational continuity and durably shields customers from the volatility of a young and dynamic AI market. This reduces dependence on individual vendors, increases traceability, and lays a sound foundation for stable, auditable operation over many years.
Draft
Deployment
European infrastructure, dedicated instance
All Platte systems run with European, ISO-certified cloud providers. Platte entirely forgoes the offerings of hyperscalers in order to guarantee full independence from outside the EU and to counter geopolitical risks.
Every Platte customer receives a dedicated, logically isolated instance in which data is stored and agentic processes are executed. In addition, all AI inference and web requests are aggregated through the Platte Privacy Gateway, which makes tracing individual requests considerably harder.
Besides the standard deployment in the Platte Managed Cloud, the isolated instance can also be hosted directly at the customer (self-hosting or managed service), which makes integrating local network services possible. Connecting dedicated or local AI inference servers is likewise possible.

Draft
Transparency
Sub-processors at a glance
| Name | Location | Service |
|---|---|---|
| Scaleway SAS | Paris, France, EU | Hosting, LLM inference |
| TensorX Ltd. | Dublin, Ireland, EUHelsinki, Finland, EU | LLM inference |
Draft
Controls
Our security controls in detail
Application & Interface Security
Are secure software development lifecycle practices (SSDLC) applied to the design, development, deployment and operation of the application?Yes
Platte follows secure development practices, including code reviews, automated and manual testing before release, and a defined change management process.
Is application security tested automatically as part of the development process?Yes
Manual and automated security testing and code reviews are performed for every release, supported by static analysis and AI-assisted analysis.
Are programming interfaces (APIs) developed, deployed and operated in line with leading security practices?Yes
All interfaces are thoroughly examined for vulnerabilities and are protected by security mechanisms that meet industry standards
Are application security risks formally assessed and remediated?Yes
Security risks are assessed during the development process. Identified vulnerabilities are prioritised and remediated before release.
Audit Assurance & Compliance
Are independent audit assurance and compliance assessments performed at least annually?Not yet
Internal reviews are carried out regularly. External audits are planned.
Are risk-based corrective actions from audit findings tracked through to completion?Yes
Findings from internal reviews are tracked and addressed. Issues reported by customers are logged, prioritised and resolved.
Business Continuity
Is a business continuity plan established, documented and maintained?Yes
Platte maintains a Business Continuity & Disaster Recovery plan covering critical business operations, continuity of the website/sales and customer support.
Are business continuity plans tested at planned intervals?Yes
Business continuity procedures, including backup restoration and failover processes, are tested regularly.
Are redundant systems and backups maintained for critical business operations?Yes
All critical systems and backups are operated redundantly
Change Control & Configuration
Are change management policies and procedures established and followed?Yes
All software changes follow a defined process, including development, code review, testing and staged rollout.
Is a risk assessment performed before proposed changes are deployed?Yes
Changes are reviewed for potential impact on security, stability and compatibility before release.
Are configuration management practices applied to ensure consistent and secure system states?Yes
Build configurations are stored in version control. Release builds follow a defined, repeatable process.
Cryptography & Encryption
Are cryptographic controls defined and implemented to protect data?Yes
Encryption for data in transit (TLS/SSL) and at rest (AES-256)
Are procedures established for managing encryption keys?Yes
Encryption keys are stored securely in a key-management solution that meets the current state of the art
Are cryptographic algorithms and protocols used that follow industry standards?Yes
Uses AES-256 for file encryption, TLS 1.2/1.3 for secure connections, and SHA-256 or stronger for integrity checks.
Datacenter Security
Are physical security perimeters and controls implemented to protect datacenter facilities?Yes
Platte operates no datacenters; our partners’ datacenters are protected to the most modern security standards
Data Security & Privacy
Are data classification and data handling policies established?Yes
Platte maintains policies for classifying and handling internal company data as well as customer data, protected by appropriate access controls. The principle of data minimisation is applied.
Are privacy policies aligned with applicable regulations (e.g. GDPR, CCPA)?Yes
A published privacy policy is maintained in compliance with the applicable regulations.
Are there procedures for secure data disposal?Yes
Platte offers secure file deletion features to customers. Internal business data follows secure disposal practices.
Are data retention policies defined and enforced?Yes
Defined retention periods are observed for support records, customer details and business documents.
Is personal data processed in accordance with legal requirements?Yes
Personal data is processed in accordance with the GDPR and applicable local regulations. Documented processes exist for legal bases, purpose limitation and data minimisation. Data processing agreements (DPAs) are concluded with customers; appropriate technical and organisational measures (including access controls, encryption and logging) are implemented.
Governance, Risk & Compliance
Is an information security management system established?Yes
Platte maintains an information security policy defining its approach to protecting assets and to risk management.
Are roles and responsibilities for information security defined and assigned?Yes
Security responsibilities are defined in the corporate policies and are overseen at management level.
Is a risk management process implemented to identify, assess and treat risks?Yes
Risks are identified and assessed in the course of ongoing operations and development planning.
Are applicable legal, regulatory and contractual requirements identified and documented?Yes
Platte monitors requirements such as the GDPR and the EU Cyber Resilience Act.
Human Resources Security
Are background checks performed on employees and contractors?Yes
New personnel with access to sensitive systems or data undergo an appropriate vetting check. All software suppliers and service providers are also thoroughly vetted before contracts are signed.
Are all employees offered security awareness training?Yes
The team keeps its knowledge of security threats and secure coding practices current. New findings are shared within the team on a regular basis.
Are access rights revoked when employment ends?Yes
Procedures exist to withdraw access to all systems and repositories upon departure.
Identity & Access Management
Is a formal user access management process implemented?Yes
Access to development systems, source code and infrastructure is restricted to authorised personnel (need-to-know principle).
Is multi-factor authentication (MFA) enforced for access to critical systems?Yes
MFA is enabled for critical systems such as source code repositories and cloud hosting accounts.
Are access rights reviewed regularly?Yes
Access rights are reviewed regularly and on personnel changes. The principle of least privilege is applied.
Are unique user identifiers assigned and the use of shared accounts prohibited?Yes
All employees have unique credentials; the use of shared accounts is avoided.
Infrastructure & Virtualisation
Are network security controls implemented to protect the infrastructure environment?Yes
Platte deploys network security controls to protect its (production and development) environments, including network segmentation, restrictive firewall rules (default-deny), hardened remote access (e.g. VPN/SSO), and logging and monitoring of security-relevant events.
Is the network architecture designed with appropriate segmentation and security zones?Yes
The network architecture is designed around a minimal attack surface and uses segmentation/security zones (e.g. separating publicly reachable components, internal services and administrative access). Access is restrictively governed.
Logging & Monitoring
Are logging and monitoring functions implemented for critical systems and security events?Yes
Logging is enabled on development systems and the web infrastructure.
Are logs reviewed and retained for an appropriate period?Yes
System and access logs are retained for an appropriate period and reviewed for anomalies.
Draft
Documents
Documents and contact
Draft
We will add these control domains to this trust center as soon as their documentation is complete:
- Security Incident Management
- Supply Chain Management
- Threat & Vulnerability Management
- Endpoint Management
Our data protection contact answers questions about privacy and security:
Responsible for data protection
Platte UG (haftungsbeschränkt) i.G.
Am Krögel 2
10179 Berlin
Germany
Email: lucas@platte.ai
Contact for data protection matters: Friedrich Theodor Gies