GOAL: shorten security review from weeks to days · AUDIENCE: CISO, DPO, procurement · CTA: Request security documentation (primary on this page). Formal, specific, verifiable register.

TRUST CENTER · UPDATED SEP 24, 2026

Trust, documented.

Every claim on this page links to a document, a control or a log. If something is missing, tell us.

DATA LOCATION
EU by default
Frankfurt primary, Stockholm backup.
MODEL TRAINING
Off by default
On every plan. Opt-in per workspace.
RETENTION
You decide
0 days to 7 years. Purge within 30 days.
ENCRYPTION
AES-256 · TLS 1.3
Customer-managed keys on Enterprise.

Certifications & frameworks

Placeholder certifications for a fictional company. Report periods are illustrative.

SOC 2 Type II

✓ In place

Security, availability and confidentiality.

Report period Apr 2025 – Mar 2026

ISO/IEC 27001:2022

✓ In place

Information security management system.

Certificate valid to 2028

ISO/IEC 42001:2023

◔ In progress

AI management system.

Audit scheduled Nov 2026

GDPR

✓ In place

EU data protection. DPA with SCCs where needed.

DPO: privacy@cairn.example

EU AI Act

✓ In place

Transparency obligations under Art. 50.

Applicable from Aug 2, 2026

CSA STAR Level 1

✓ In place

Cloud security self-assessment.

Published Feb 2026

Where your data goes

One request, end to end. Every hop stays inside the EU region you choose. Select a step to see what is stored and for how long.

STORED
Encrypted workspace data
RETENTION
Your retention setting (default 30 days)
WHO CAN ACCESS
Your admins; Cairn support only with your time-boxed grant

Controls you can check yourself

These are the actual workspace settings, shown here as a preview. Admins change them in the console; every change is written to the audit log.

WORKSPACE · DATA CONTROLSPREVIEW

Conversations in this workspace are kept for 30 days, then permanently deleted. They are never used to train or improve any model.

Export all data Delete workspace

Subprocessors

EntityPurposeLocationCustomer data
Nordvolt Cloud GmbHHosting and computeGermanyYes, encrypted
Fjord Storage ABBackup storageSwedenYes, encrypted
Postwise Ltd.Transactional emailIrelandEmail address only
Ledgerline Inc.Billing and invoicingUnited States (SCCs)Billing contact only
Helpdeck OySupport ticketsFinlandOnly what you send us
Signalhaus GmbHError monitoringGermanyNo content, metadata only

Fictional entities. Changes announced 30 days in advance · Subscribe to changes

Documents

EU AI ACT · TRANSPARENCY

How we meet Article 50

Placeholder summary. Not legal advice; your obligations depend on how you deploy Cairn.

  • AI interaction disclosure. Every assistant and site widget says it is an AI before the first reply.
  • Synthetic content marking. Generated images carry a visible label and C2PA Content Credentials.
  • Model documentation. Model cards list intended use, limits and evaluations. Read Summit 2.1’s.
  • Human oversight. Agents pause for approval before any external action.

90-day uptime

Full status page →
Assistant99.98%
Agents99.95%
API99.99%
Console99.97%
Jun 26, 2026 ■ operational ■ degraded ■ outage · illustrative Today

Found a vulnerability?

Email security@cairn.example or use our PGP key. We acknowledge within 24 hours, never pursue good-faith research, and pay bounties from $500 to $25,000.

/.well-known/security.txt
REQUEST SECURITY DOCUMENTATION~2 MIN

Get the full security package

Documents
Some reports are confidential. By checking the box you accept our mutual NDA (v2.1, 2 pages). No signature, no call.
Accept the NDA to request confidential reports, or deselect them.
LATENT Kit ↗
Start free Book a demo