All tools
EU-sovereign by design

EU-sovereign AI Act compliance

Veritome is built in Europe and hosted in Europe — EU data residency, EU model inference, GDPR-native. For a tool that holds your regulatory evidence that is not a detail; it is the point.

Data residency

EU only — Hetzner (Germany). Your compliance data is stored and processed in the EU. The supporting services outside it — email, payments, optional single sign-on and the optional evidence connectors — are named in our sub-processor register and operate under EU Standard Contractual Clauses.

AI inference

Mistral (France) — a commercial EU model that does not train on your data.

Encryption

Encrypted at rest and in transit; EU-only encrypted backups.

GDPR-native

Built to GDPR from the ground up — DPA and sub-processor list published.

Why it matters

Where the data lives is the control

If your governance tool ships EU personal data to a processor outside the Union, you have created the exact transfer risk you are trying to govern. Your evidence — the record you would hand a regulator — stays in the EU, and every processor is listed where you can check it.

Common questions

Straight answers

Where is my compliance data stored?

In the EU. Veritome runs on EU infrastructure (Hetzner, Germany), with encryption at rest on the database volume and on the object storage that holds your evidence. Every processor outside the EU is named in our sub-processor register, with the safeguard that applies to it.

Which AI model does Veritome use?

Veritome uses Mistral, a commercial EU model hosted in France, and does not train models on your data.

Is Veritome GDPR-compliant?

GDPR is the design baseline: EU hosting, EU model inference, a Data Processing Agreement and the full sub-processor register, all published in the Trust Centre. Compliance under the GDPR is shared — the DPA sets out what we do as processor and what remains yours as controller.

See the Trust Centre →Run the exposure scan