All tools
EU-sovereign by design

EU-sovereign AI Act compliance

Veritome is built in Europe and hosted in Europe — EU data residency, EU model inference, GDPR-native. For a tool that holds your regulatory evidence, that isn't a detail; it's the point.

What good looks like

Your compliance evidence — the record you'd hand a regulator — is stored in the EU, and you can check every processor from the Trust Center.

Why it matters

If your GRC tool ships EU personal data to a US processor, you've created the exact transfer risk you're trying to govern. Where the data lives is the control.

Get started with Veritome Free tools flow into Veritome when you're ready.
Data residency
EU only — Hetzner (Germany). Your compliance data is stored and processed in the EU. The supporting services outside it — email, payments, optional single sign-on and the optional evidence connectors — are named in our sub-processor register and operate under EU Standard Contractual Clauses.
AI inference
Mistral (France) — a commercial EU model that does not train on your data.
Encryption
Encrypted at rest and in transit; EU-only encrypted backups.
GDPR-native
Built to GDPR from the ground up — DPA + sub-processor list available.

Common questions

Where is my compliance data stored?
In the EU. Veritome runs on EU infrastructure (Hetzner, Germany), with encryption at rest on the database volume and on the object storage that holds your evidence. Every processor outside the EU is named in our sub-processor register, with the safeguard that applies to it.
Which AI model does Veritome use?
Veritome uses Mistral, a commercial EU model hosted in France, and does not train models on your data.
Is Veritome GDPR-compliant?
GDPR is the design baseline: EU hosting, EU model inference, a Data Processing Agreement and the full sub-processor register, all published in the Trust Center. Compliance under the GDPR is shared — the DPA sets out what we do as processor and what remains yours as controller.