Security
Our commitment to uncompromising security
At Neuver Oy we understand that the security of your company's data is the cornerstone of our work. We build the Service to meet the EU General Data Protection Regulation (GDPR) and the transparency duties of the EU AI Act, and we say plainly what the Service does with your data.
Layered protection
Encryption at every stage
Connections between you and the Service, and between the Service and every external provider, are encrypted in transit. Stored data is encrypted at rest. Traffic between our own containers stays on the private server network.
Network and infrastructure security
We use Cloudflare's protection against denial-of-service (DDoS) attacks and to secure network traffic. This also helps hide the real IP addresses of our servers, adding an extra layer of security.
Flexible and secure login options
We offer several login options. If your organisation uses Microsoft services, you can use existing Microsoft accounts to log in. In that case users do not need to create new credentials, and you can seamlessly use your company's existing security practices, such as multi-factor authentication (MFA).
Granular access control
Within the service you can define precisely who sees what. Access rights can be managed per group and per folder, ensuring that employees can access only the information they are permitted to see.
Data location and secure processing
Hosted in Finland
The servers, databases, search indexes and document storage are in Finland. If your organisation uses agent workspaces, their saved files and templates are stored in Cloudflare R2 in the EU. AI processing, the network edge and provider support may involve processing outside the EU/EEA. Our Privacy Policy describes international transfers.
Secure use of AI
We use the market-leading AI models through APIs. We have designed the process with security first:
- Only what the request needs: For a question, the AI model receives the question, the conversation so far and the passages of your documents that are relevant to it. For document analysis, it receives the pages or the file being analysed. Nothing is sent that the feature does not need.
- Temporary retention: Providers may retain request data for abuse monitoring, feature storage or legal obligations. Contact privacy@neuvise.com for the retention terms of the features you use.
- Strict agreements: Every AI provider we use is bound by a data processing agreement that limits the use of your data to serving your request. A provider that cannot meet our agreement with you is not used for your data.
- No model training: Your company's data is not used to train AI models. Our agreement with you prohibits it, and we use only providers and account settings that honour that.
Tailored security solutions
We understand that every company has unique security requirements. We are ready to listen to your needs and implement tailored solutions. Examples of the possibilities include:
- Isolating the service behind your company's own VPN network.
- Dedicated server resources reserved for your use only.
- Customer-specific backup practices.
Continuous monitoring and development
We monitor the Service for failures and security events, review changes and vulnerabilities, and keep our measures in line with the risks. Where we have audit reports, we share them with customers.
Contact
Questions about our security practices? Contact us:
Neuver Oy
Security and data questions
Yes. Neuvise is built for organizations that handle sensitive information. Access is controlled at the company, group and personal level, data is encrypted, and the AI only retrieves documents the user is authorized to see.
The servers, databases, search indexes and document storage are in Finland. If your organisation uses agent workspaces, their saved files and templates are stored in Cloudflare R2 in the EU. Some AI providers process requests in the United States. Our Privacy Policy describes international transfers.
No. Our agreement with you prohibits training AI models on your data, and we use only providers and account settings that honour that.
We process personal data under the GDPR. Our Privacy Policy describes the processing and your rights. Your organisation remains responsible for the data it uploads and may need its own impact assessment for sensitive or regulated data. Contact us for the information needed to assess your use.
No. Every search query enforces permission filters tied to your company, your groups and your personal files, and files are isolated per organization in storage. Users cannot reach documents outside their access.
Yes. The AI assistant uses the same permission filters as normal search, derived from your authenticated identity rather than anything the model is told, so it can only retrieve documents you are allowed to access.
For a question, the model receives your question, the conversation and the relevant passages of your documents; for document analysis it receives the pages or the file being analysed. Retention depends on the provider and feature; contact privacy@neuvise.com for details.
