Trust centre
This is our consolidated overview of how we work with privacy, security and responsibility. The page is updated as documentation is published.
Overall approach
The EU AI Act and GDPR underpin the architecture from the first version. We do not publish security guarantees or certifications before they can be documented by an independent party.
Privacy
We collect as little as possible, and only what the purpose requires.
- Data minimisation in all forms and interfaces.
- A defined legal basis for each processing activity.
- No use of customer content for model training without an explicit agreement.
- The right to access, rectification and erasure.
Data security
Security work follows the principle of least privilege.
- Role-based access to all systems.
- Encryption of data in transit.
- Event logging for administrative operations.
- Server-side validation of all submitted information.
Model testing
The evaluation framework will be published with the first model version, describing method, dataset, date, model version and limitations for every result.
Responsible development
We define where the model should not be used just as clearly as where it should.
- No automated decisions without human control.
- No use as the sole basis for medical or legal decisions.
- No use for surveillance of individuals.
Limitations
The model is in development. It can produce incorrect answers, and all results must be verified by a qualified person before use.
Incident reporting
Security incidents and vulnerabilities can be reported directly to the company. We confirm receipt and keep the reporter updated throughout handling.
Document index
No documents have been published yet. Model card, data statement, security overview and evaluation method will be published with the first model version.
Security contact point
Report vulnerabilities and security incidents to zivos@zivos.no, marked «Security».
zivos@zivos.no