Security & Compliance

Built to pass your security review

Everything your DPO, CISO, and procurement team need to approve Neuraplox — in plain terms, with no overstated claims.

All customer data · STACKIT EU01, Nürnberg, GermanyNo US parent · no AWS/Azure/GCP fallback

Infrastructure attestation

Runs on BSI C5 Typ 2 attested infrastructure

Neuraplox runs on STACKIT SKE, whose infrastructure holds a BSI C5 Typ 2attestation. The attestation is the infrastructure provider's — it is not a Neuraplox certification. It means the cloud layer we build on was independently audited against the German BSI Cloud Computing Compliance Criteria Catalogue.

What we do today

Controls that ship with every tenant

EU-sovereign hosting

Hosted exclusively in Germany (STACKIT, Nürnberg). No AWS/Azure/GCP fallback, no US parent company — your data never leaves the jurisdiction.

Reversible PII-masking

Personal data is detected and masked before any model call, then restored on the way back — automatically, per-tenant detection language.

Tamper-evident audit trail

Every action is written to an append-only, hashchain-verified log your auditors can replay. Integrity is checked on a schedule.

DSGVO by design

DSGVO-compliant processing, Art. 28 order-processing terms, and Art. 17 erasure support built into the platform.

Certifications — in progress

What we are pursuing

We do not yet hold the certifications below. We are actively pursuing them and list them here for transparency, not as current credentials.

ISO/IEC 27001

In Vorbereitung

Information security management — Zertifizierung in Vorbereitung.

IDW PS 861

In Vorbereitung

Prüfung von KI-Systemen — Testat angestrebt (Wirksamkeit ab Betriebshistorie).

IDW PS 880

In Vorbereitung

Softwarebescheinigung — gebündelt mit der PS-861-Angemessenheitsprüfung.

Documentation

Proof you can hand to procurement

Draft documents — contact us for the executed version.

Ready to put it in front of your security team?