§ I · Security

EU-only. Zero retention. Audit before you sign.

A legal-tech vendor's security posture should read like a DPA, not a marketing page. This is what we will publish, defend in writing, and walk an auditor through — before contract signature.

EU data residency

Frankfurt (eu-central-1) + Warsaw (eu-central-2). No transfers outside EEA.

Zero AI training

Customer data never enters any training set, ours or anyone else's.

Zero retention

Model providers see your data only in-flight, never at rest.

ISO 27001 · in progress

Stage 1 audit Q3 2026. SOC 2 Type II evidence collection underway.

§ II · Claims we'll defend in writing

Six commitments. Each tied to a contract clause.

CommitmentWhere it livesStatus
EU-only data residencyCustomer data is stored and processed only in Frankfurt and Warsaw AWS regions.DPA § 4.1in force
Zero AI training on customer dataNo customer prompt, document, or output is used to train any model. Confirmed by sub-processor contracts.DPA § 6.3in force
Zero retention by model providersAll LLM calls run under no-retention enterprise agreements. No customer data persists outside our EU tenant.DPA § 5.2in force
Encryption in transit and at restTLS 1.3 in transit. AES-256 at rest. Customer-managed keys (CMK) available on Enterprise tier.DPA § 7.1in force
ISO 27001 certificationStage 1 audit booked for Q3 2026. Bureau Veritas selected as registrar.in progressin progress
SOC 2 Type II reportEvidence-collection window opens 01.07.2026. First report expected Q1 2027.roadmapon roadmap
§ III · Sub-processors

Five sub-processors. Disclosed in the DPA. Auditable before signature.

ProviderRegionJurisdiction
Amazon Web Services EMEA SARLCompute, storage, networkingFrankfurt · WarsawEU
Anthropic Ireland Ltd.Language model inference · no-retention enterprise agreementDublin · FrankfurtEU
Mistral AI SASPolish-language model inference · EU sovereign deploymentParisEU
Plausible Insights OÜCookieless analytics · aggregate, anonymizedTallinnEU
Resend Sp. z o.o.Transactional email · DKIM + ARC signed, EU-routedWarsawEU
§ V · Where the data goes

A query, end to end. Every hop in EU jurisdiction.

Annotations
  1. [1] Corpus retrieval: public primary sources only, fetched read-only and indexed within the EU tenant.
  2. [2] Citation verifier: every model output is matched back to the source paragraph before display.
  3. [3] Refusal-when-silent: if no primary source resolves the question, the answer says so. No fabricated sygnatury.
§ VI · EU AI Act posture

A limited-risk system, transparently used.

Grasperly is classified as a limited-risk AI system under the EU AI Act (Regulation (EU) 2024/1689). The platform supports natural-language interaction with verified case-law and assists with drafting and deadline arithmetic; it does not autonomously file pleadings, accept service of process, or take regulatory action on behalf of the firm.[1]

Every AI-generated output ships with an unambiguous indicator (the signal-teal citation marks throughout the product) and a one-click expansion to the supporting primary source. The platform meets the transparency obligations of Article 50 of the regulation and exceeds them in legal-research outputs.[2]

Sources
  1. [1] Regulation (EU) 2024/1689 · EU AI Act · Art. 6 risk classification · eur-lex.europa.eu
  2. [2] Regulation (EU) 2024/1689 · EU AI Act · Art. 50 transparency obligations · eur-lex.europa.eu
§ Floor, not ceiling

Zero training on customer data is the floor. ISO 27001 and SOC 2 are the ceiling we're walking toward.

Security commitments · DPA §§ 6.3 + 11

Read the DPA before you sign.

Warsaw · Stockholm · GDPR Art. 28 compliant