Security, compliance & data protection
One platform. Every AI model. Absolute data security — here is the evidence.
DeepMask GmbH, based in Munich, operates an AI platform that brings more than 25 leading AI models together in a single, GDPR-compliant interface. Users switch between models mid-conversation, compare answers and pick the right tool for each task — with no vendor lock-in and no context switching.
Operations run on German infrastructure: the primary hosting partner is the Schwarz Group's sovereign German cloud (STACKIT), complemented by EU regions for redundancy and scalability. Inputs and responses are not used to train models. Law firms, patent attorneys, associations, engineering offices and companies from the energy and financial sectors use DeepMask every day.
DeepMask is fully GDPR compliant. Data processing agreement under Art. 28, technical and organisational measures under Art. 32, an appointed external data protection officer and a record of processing activities under Art. 30.
The AI Act (Regulation (EU) 2024/1689) distinguishes between provider and deployer. DeepMask is the provider of the platform, you are the deployer within your own organisation — here is what each role entails and how we support you.
The primary hosting partner is the Schwarz Group's sovereign German cloud (STACKIT) — certified to ISO 27001 and BSI C5. Beyond that, only EU regions are used, so your data never leaves European borders.
TLS 1.3 for all connections, AES-256 for data at rest in databases, object storage and backups. Central key management with regular rotation and strict tenant separation per organisation.
Your inputs and the generated responses are not used to train AI models. This is contractually agreed with every model provider engaged and documented in the technical and organisational measures.
Law firms, patent attorneys, tax advisors and doctors use DeepMask. For these professions we provide the confidentiality undertaking and instruction under Section 203 of the German Criminal Code as an annex to the DPA.
An information security management system to ISO/IEC 27001 is being established; certification is in progress. Until it is completed we evidence security through the certifications of our infrastructure partners.