Gathersense

Security & data residency

Your data, where it belongs.

EU-based, with data resident on the infrastructure you choose. The AI never trains on your data.

The posture, in plain words

Gathersense is EU-based. We build and operate the platform to ISO 27001 standards. We are GDPR compliant. The platform is designed for EU AI Act alignment, and it is audit-ready by construction. For enterprise customers we deploy dedicated, single-tenant environments under strict security controls, with case and contract data resident on the infrastructure the customer chooses. The heavy AI work runs on infrastructure built for it and never trains on customer data. Data residency is part of the architecture, not bolted on.

Standards

Built to the standards that matter.

The precision of these words matters. We write what is true and never claim a certification we do not hold.

Built to ISO 27001 standards

We operate the platform to ISO 27001 standards.

GDPR compliant

A legal posture, by design.

EU AI Act aligned

Designed for EU AI Act alignment.

Audit-ready by construction

Every review is recorded the moment it runs.

How it works

Where the data lives, what the AI does, and what is kept.

A dedicated environment, inside your own perimeter

For organisations with strict security requirements, a single-tenant environment, separate from any other team, with data resident on the infrastructure you choose. The data that must stay in region stays in region.

No training on your data. Nothing wanders

The heavy AI work runs on infrastructure built for it and never trains on your data. A conversation about one case does not see another. A matter does not leak into another matter.

Audit-ready by construction

Every output is recorded the moment it runs, so the work can be audited at any time. The answer to “show me how the AI got there” is already written.

Asked and answered

The questions security teams ask first.

Plain answers, in the same words we put in writing.

Where does our data live?

On the infrastructure you choose, in region. For enterprise customers we deploy a dedicated, single-tenant environment under strict security controls, separate from any other team.

Does the AI train on our documents?

No. The heavy AI work runs on infrastructure built for it and never trains on your data.

Can one matter see another?

No. The assistant is scoped to the work in front of it. A document in one matter is never visible to an assistant in another, and a workspace's data stays inside the workspace.

How do we audit what the AI did?

Every output is recorded the moment it runs. Reviews can be replayed and exported, so the answer to “show me how the AI got there” is already written.

Who can access our environment?

Access is role-based, set per team. Admin, manager, and member roles decide who sees which matters. People see only the matters they should.

Which certifications do you hold?

We do not claim certifications we do not hold. We build and operate the platform to ISO 27001 standards, we are GDPR compliant, and the platform is designed for EU AI Act alignment. Those are the words we put in contracts too.

Procurement

Everything your security team needs to sign off.

For DPAs, subprocessors, and security documentation, see our trust pack or talk to us.

Built in Europe, for the rules Europe takes seriously.

Set up a working session. We will walk your team through where the data lives and how the environment is set up.