Security & data
Where your data lives, and who can reach it.
A sovereignty company should be transparent by default. This page sets out how we handle data. Items marked for confirmation are being finalised before launch.
Our products run either on Vivaldi’s sovereign cloud in the Netherlands and Germany, or entirely inside your own infrastructure. In the on-premise option the only external dependency is your own Mistral account, or a fully local model.
Hosting & data residency
All hosting is within the EU: on our sovereign cloud in the Netherlands and Germany, or on your own infrastructure. No data is processed outside the EU. {{ CONFIRM: data-centre providers and regions }}.
Models
We build on Mistral and local, open-weight models. Your data is never sent to US AI providers and never used to train third-party models. In the on-premise option you use your own Mistral account or a fully local model.
Sub-processors
We keep sub-processors to a minimum, all within the EU. {{ CONFIRM: current sub-processor list }}.
Encryption
Data is encrypted in transit and at rest. {{ CONFIRM: encryption standards and key management }}.
Retention & deletion
Data is kept only as long as the service needs it, and deleted on request. {{ CONFIRM: retention periods }}.
Certifications
Our framework draws on ISO 27001, NIST CSF and NIS2. {{ CONFIRM: ISO 27001 certification status / roadmap }}.
Data processing agreement
We provide a GDPR-compliant DPA on request. {{ CONFIRM: DPA link or contact }}.
For a full security review or a DPA, contact info@vivaldisecurity.com.