Security you can be trusted on.
A summary of how we protect the data you send us. Full technical details are available under NDA for prospects that need them.
Our security principles.
Four ideas that shape how we build and operate the service.
Defence in depth
No single control is asked to carry all the weight. Multiple layers each do their share, so no single miss is catastrophic.
Least privilege
People and systems get only the access needed for the job, and no more. Access is reviewed and revoked when it stops being needed.
Encryption everywhere
Data is encrypted in transit and at rest, using industry-standard, well-reviewed cryptography.
Compliance-first
Our security programme is aligned with GDPR, EU AI Act, and ISO 27001 controls, and is designed to keep passing external audits.
How we protect your data.
The controls that back up the principles above. Kept at a summary level here on purpose.
Compliance and alignments.
Public frameworks our controls are mapped to.
GDPR
EU General Data Protection Regulation. Full alignment across processing, retention, and data-subject rights.
EU AI Act
Our logging, transparency, and human-oversight controls are mapped to the relevant articles of the EU AI Act.
ISO 27001 controls
Our information security programme is designed against the ISO 27001 control catalogue.
SOC 2 readiness
SOC 2 Type I readiness is in progress. Ask us where we are for an up-to-date read.
What GDPR, the EU AI Act, and EU data residency require.
A plain-language read for procurement, legal, and IT teams evaluating AI adoption. What each rule asks of you, and how Ciralgo answers it.
GDPR
Applies the moment a prompt contains personal data. You need a lawful basis, data minimisation, subject rights, transfer safeguards, and a signed DPA with every processor in the chain, including the AI provider.
EU AI Act
For most SME Copilot rollouts you are a deployer of limited-risk AI. You must disclose AI use, keep records of the systems you deploy, and put staff AI literacy in place. High-risk deployer obligations apply from 2 August 2026.
EU data residency
Personal data processed and stored inside the EU, not shipped to US or Asian data centers. Since Schrems II, transfers outside the EU need SCCs plus a transfer impact assessment. Staying inside the EU avoids the extra paperwork.
How Ciralgo answers all three
Request path stays inside the EU. Every provider call is logged in a tamper-evident audit trail. A DPA is signed with every customer. Procurement gets one place to check EU AI Act and GDPR compliance status.
Common questions about EU AI compliance.
The questions procurement, legal, and IT teams ask most before rolling out Copilot or another AI tool.
Is Copilot GDPR-compliant out of the box?
Copilot inherits the compliance posture of your Microsoft 365 tenant, which is a solid starting point. GDPR compliance, however, is a deployment question, not a product question. You still need a lawful basis, a DPA with Microsoft, and internal controls that prevent staff from pasting third-party personal data into prompts. For the practical Microsoft Purview DLP setup that operationalises these controls in 30 days, see our Copilot safety baseline. Broader supervisory guidance is collected by the European Data Protection Board.
Does the EU AI Act apply to my SME?
Yes, but usually as a deployer of limited-risk AI rather than a high-risk provider. Your obligations are transparency to end users, record-keeping for the AI systems you use, and an AI literacy program for staff. If you use AI in recruitment, credit decisions, or other high-risk contexts listed in Annex III, deployer obligations apply from 2 August 2026. The full text and phased timeline sit on the official EU AI Act page.
What is EU data residency and why does it matter?
EU data residency means processing and storing personal data inside the European Union, not exporting it to third countries for computation. It matters because transfers outside the EU require additional safeguards, typically Standard Contractual Clauses plus a transfer impact assessment, which add procurement and legal work. Keeping the request path inside the EU avoids that friction and simplifies GDPR alignment for the whole rollout.
Does Ciralgo sign a DPA?
Yes. Ciralgo signs a Data Processing Agreement with every customer as part of onboarding. The DPA covers the roles of controller and processor, the sub-processors in the chain, the security measures in place, and the process for handling data subject requests. Enterprise customers can request custom clauses ahead of signing.
Report a vulnerability.
If you think you have found a security issue, we want to hear from you.
-
Good-faith research is welcome. If you follow the guidelines below, we will not pursue legal action against you.
-
Do not access other customers' data. If you find a way, tell us before proving it further.
-
Give us time to fix before disclosing publicly. We will agree a disclosure timeline with you in writing.
Request the full whitepaper.
Prospects with an evaluation in flight can get our security whitepaper under NDA.
Ciralgo B.V., Amsterdam, the Netherlands
