Security and Trust

Trust is essential to responsible AI transformation

casaios asks organizations to bring their AI activity, governance decisions and workforce data into one platform. That only works if we are clear about how the platform is built, where data is processed and who is involved. This page describes our current position and is updated as the platform develops.

Data hosting

Customer data is hosted within the European Union.

Tenant separation

Each customer organization operates in its own logically separated environment.

Separation is implemented through separate database schemas per organization combined with row-level security.

Role-based access

Access follows defined roles, so employees, managers, expert functions and administrators see the information and actions appropriate to their responsibilities.

Audit and traceability

Key changes, decisions, approvals and reviews remain traceable within the platform, so governance records can be reconstructed rather than reassembled manually.

Subprocessors

  • OpenAI

    Purpose
    AI assistant and AI-supported features
    Note
    Processing may occur outside the European Union
  • HubSpot

    Purpose
    Customer relationship management and business communication
    Note
    Processing may occur outside the European Union
  • Make.com

    Purpose
    Workflow automation between business systems
    Note
    Processing may occur outside the European Union

While customer data is hosted within the European Union, some subprocessors may process data outside the EU. Where that applies, transfers rely on the safeguards set out in our data processing documentation.

Responsible AI

  • Customer data is not used to train models.

    Content processed by the AI assistant is not used to train or improve the underlying models.

  • The assistant recommends, people decide.

    The assistant prepares and explains. It does not approve its own recommendations or publish governance outcomes without responsible human review.

  • Human accountability stays assigned.

    Every governed AI activity has a named owner, and assistant contributions remain visible alongside human decisions.

Explore the casaios AI Assistant

Legal documentation

Compliance documentation, including our data processing agreement, is available in the casaios trust portal.

Visit the Trust PortalPrivacy PolicyImprint

Security contact

Report a security concern or suspected vulnerability to: info@casaios.ai

We take reports seriously and will respond. Please give us reasonable time to investigate before disclosing publicly.

For all other enquiries: info@casaios.ai

See how casaios works in your organization

Walk through the platform with our team, or ask a specific question about how casaios would fit your environment.