Skip to main content
InApp-Agent

Trust

Your data stays in France, protected and kept separate.

Handing actions to an agent means knowing where your data is, who keeps the keys, what the agent is allowed to do and what trace remains. Here is what is in place today, and what is defined with you.

Hosting

Hosting, as it runs today

  • Hosted in France, backup site in Germany

    Applications run in data centres in France (Paris region). A backup site in Germany (Frankfurt region) takes over should the first one stop. The database is in Paris; an up-to-date copy is kept in Frankfurt.

  • Encrypted at every step, with keys we keep

    Your data is unreadable to anyone not authorised, in transit as in storage. The databases’ encryption keys are kept by STARTUP-UP in a dedicated security module, separate from the platform hosting the data. One key per database, impossible to copy. Every use of a key is recorded; we can revoke it.

  • Kept separate per customer

    Your data never mixes with another customer’s: the separation is enforced inside the database itself, including for what the agent can read.

  • Traced

    Every agent action is recorded: you always know who did what, on which case, and when. Passwords and access keys never appear in code or in exchanges with the AI.

Continuity and recovery are set out in the contract. Development and test environments are separate from production.

The principles we hold

  • Permissions come from the server, never from the AI

    Who you are and what you are allowed to do is decided by the server. No typed text, no page read and no model can grant itself a permission.

  • Every action leaves a trace

    An executed action is recorded with its author, its object and its outcome. That is what makes the agent’s report verifiable.

  • Data stays with its owner

    Your application keeps its reference data. The agent reads and writes within the limits you set, not beyond.

  • Separation between organisations

    One customer's conversations, documents and preferences are never shared with another. That separation is verified during the pilot.

What this brings under the GDPR

A technical reading of our measures, article by article. The legal qualification of your processing is for your DPO; we provide the material.

  • Security of processing (art. 32)

    Encryption by a dedicated security module, one key per database, key renewal on our initiative, every key access recorded, key administration kept separate from data administration.

  • Processors (art. 28)

    You receive the list of providers involved — hosting, database, authorised model providers —, the data transmitted to each and its retention period. Any use of our keys by a provider is recorded on our side.

  • Data breach (art. 33 and 34)

    Data encrypted with a key the attacker does not hold remains unintelligible: in the event of a storage or backup leak, the duty to inform data subjects is assessed in light of that measure.

  • Erasure (art. 17)

    Destroying a key makes the data and backups it protected unreadable: a technical means of erasure where physical deletion is not possible, governed by the retention policy.

  • Transfers (chapter V)

    Production is hosted in the European Union. Where AI models process data is identified separately for the chosen configuration and recorded in the project commitments.

  • Training

    Your data stays yours: never used to train a shared model, never for other customers. Users see what the agent has kept, and can correct or erase it.

What we put in place under the EU AI Act

InApp-Agent is an assistant that carries out tasks inside a business application, under the control of its users. The level of obligations depends on how you use it; it is qualified with you during scoping.

  • Transparency

    Users know they are addressing an agent: the panel carries its name, its answers cite their sources, missing information is stated as missing.

  • Human oversight

    An action that changes data requires explicit approval, adjustable feature by feature. The agent says what it will not do on your behalf.

  • Action records

    Every action is recorded server-side with its author, object and result; the history is available in your application.

  • Documentation

    Description of the system, the models used, the data accessible and the capabilities opened, delivered with the project and kept up to date.

  • Scope of use

    The agent is not designed to take legal or similarly significant decisions about people on its own. If your application falls within a high-risk area under the regulation, scoping says so and the perimeter adapts.

  • Continuous improvement

    Vigie spots what gets in users’ way and suggests better. No change without your approval, no monitoring of individuals.

Frequently asked questions

Where is the data hosted?

In data centres in France (Paris region), with a backup site in Germany; database in Paris, up-to-date copy in Frankfurt. Where AI models process your data is specified for the chosen configuration.

Who holds the encryption keys?

STARTUP-UP, in a dedicated security module separate from the platform hosting the data. The keys cannot be copied — by us or by the hosting provider. Every use is recorded on our side and we can revoke a key.

Is my data used to train a model?

No. Your data stays yours: never used to train a shared model, never for other customers. The terms of the model providers chosen for your configuration are shared with you.

What about the CLOUD Act?

The data is hosted in Europe but operated by providers subject to their national law. Encryption with our own keys does not place the data beyond the reach of an order served on the operator; but the operator only holds encrypted data, without the decryption key, which stays with us: what it could hand over is unreadable, and any use of the key is recorded on our side. For contexts that require it, dedicated private AI and installation on your own servers are assessed with you.