Security

How we handle customer data.

How we work with your data

Subduxion works with confidential manufacturing data every day. These are the principles we hold ourselves to, in plain language. Where a commitment is still being built out, we say so.

Where your data lives

A deployment you control

Our models are designed to run on your own premises or in an EU tenant. Customer data does not leave the environment you choose.

EU by default

Processing and storage take place in the European Union. Nothing is transferred outside the EEA without your written agreement.

Retention you decide

Customer data is kept only as long as you want it, and deleted on request. You can ask for a copy at any time.

How we use it

No training on your data without a lawful basis

Your files and corrections are not used to train a model unless a lawful basis for that is recorded and you know about it.

Strict separation between customers

Each customer's data is isolated. Nothing you share is visible to, or used for, another customer.

Access on a need-to-know basis

Only named people at Subduxion can access customer data, only for support you asked for, and every access is logged.

How we work

Security is part of engineering

Data is encrypted in transit and at rest, secrets are managed centrally, and security review is part of how we ship.

Responsible disclosure

Found a vulnerability? Our security.txt tells you how to reach us. We respond, fix, and credit.

Regulation as the baseline

GDPR and the EU Data Act shape how we build. Export-controlled and NDA-bound material is handled under those rules from the first upload.

Questions about how we handle your data? Contact us.