Security, compliance & data protection

Trust Center

One platform. Every AI model. Absolute data security — here is the evidence.

About DeepMask

DeepMask GmbH, based in Munich, operates an AI platform that brings more than 25 leading AI models together in a single, GDPR-compliant interface. Users switch between models mid-conversation, compare answers and pick the right tool for each task — with no vendor lock-in and no context switching.

Operations run on German infrastructure: the primary hosting partner is the Schwarz Group's sovereign German cloud (STACKIT), complemented by EU regions for redundancy and scalability. Inputs and responses are not used to train models. Law firms, patent attorneys, associations, engineering offices and companies from the energy and financial sectors use DeepMask every day.

Your Trust Center contact

contact@deepmask.io

Questions on data protection, security and compliance

GDPR compliance badge

GDPR compliance

DeepMask is fully GDPR compliant. Data processing agreement under Art. 28, technical and organisational measures under Art. 32, an appointed external data protection officer and a record of processing activities under Art. 30.

EU AI Act compliance badge

EU AI Act

The AI Act (Regulation (EU) 2024/1689) distinguishes between provider and deployer. DeepMask is the provider of the platform, you are the deployer within your own organisation — here is what each role entails and how we support you.

Hosting in Germany compliance badge

Hosting in Germany

The primary hosting partner is the Schwarz Group's sovereign German cloud (STACKIT) — certified to ISO 27001 and BSI C5. Beyond that, only EU regions are used, so your data never leaves European borders.

Encryption compliance badge

Enterprise-grade encryption

TLS 1.3 for all connections, AES-256 for data at rest in databases, object storage and backups. Central key management with regular rotation and strict tenant separation per organisation.

No model training compliance badge

Never used for model training

Your inputs and the generated responses are not used to train AI models. This is contractually agreed with every model provider engaged and documented in the technical and organisational measures.

Professional secrecy compliance badge

Professional secrecy

Law firms, patent attorneys, tax advisors and doctors use DeepMask. For these professions we provide the confidentiality undertaking and instruction under Section 203 of the German Criminal Code as an annex to the DPA.

ISO 27001 compliance badge

ISO/IEC 27001Certification in progress

An information security management system to ISO/IEC 27001 is being established; certification is in progress. Until it is completed we evidence security through the certifications of our infrastructure partners.

Technical and organisational measures

Show all
Hosting & physical access control
  • Operation in certified data centres in Germany
  • STACKIT: ISO 27001 and BSI C5
  • No own on-premise processing facilities
Show more
System and data access control
  • Multi-factor authentication, SSO and SAML
  • Role-based access control (RBAC)
  • No access to chat content during normal operations
Show more
Encryption & separation
  • TLS 1.3 for all connections
  • AES-256 for data at rest and backups
  • Strict tenant separation per organisation
Show more
AI-specific measures
  • No training on your inputs
  • No prompt retention at the model providers
  • Preferred routing to EU endpoints
Show more