Security
The security of your data is our highest priority.
AI employees work with your data. That is why we do not treat data sovereignty as small print, but as part of our commitment: processing in Germany, encrypted in transit and at rest, and no use of your data for model training.
Corporations and mid-sized companies entrust their intelligence data to scoreprise.





Certified infrastructure
Documented, not asserted: audited by third parties, not by ourselves.
These certificates apply to the hosting infrastructure in Germany (Hetzner) on which our systems run, not as scoreprise.AI's own company certification. The data centres are located in Germany and comply with the GDPR.
Your data does not train models.
What your AI employees process serves your task alone. No sharing with model providers for training purposes, no learning from your content. Full stop.
01
Storage
Exclusively in data centres in Germany (Hetzner).
02
Encryption
TLS 1.2+ in transit, AES-256 at rest.
03
Access
Role-based, on a need-to-know basis.
04
Deletion
A fixed deletion plan for each project phase, earlier on request.
Reliable in day-to-day operation.
Security and data protection in detail.
IT and data protection can check what is stated here point by point during the review.
Reliable data basis
Security architecture
Operation & response
Data sovereignty & export
Legal documents
What you can rely on.
01
Hosting in Germany
Processing exclusively in German data centres (Hetzner). Your data does not leave the EU.
02
GDPR-compliant
Processing in accordance with the GDPR, with a data processing agreement. Encrypted in transit (TLS 1.2+) and at rest (AES-256).
03
Reliable operation
Service levels with clear response times: 4 hours for critical matters, 8 hours in normal operation.
04
Confidentiality
NDA as standard. What stays with you, stays with you, including during our work together.
05
No lock-in
The configurations of your AI employees belong to you. Full export in JSON, CSV and Markdown, at any time.
06
You stay in control
You see what your AI employees work with and what they deliver, before anything goes out.
The most common audit questions
For IT and data protection: what every audit asks.
Where is our data stored and processed?+
Exclusively in data centres in Germany (Hetzner). There is no transfer to third countries.
Is there a data processing agreement (DPA)?+
Yes. Processing takes place in accordance with the GDPR on the basis of a data processing agreement that governs the subject matter, duration and deletion.
Who has access to our data, and how is that access protected?+
Access is role-based and follows the need-to-know principle. All staff are trained regularly in data protection.
Is our data used to train AI models?+
No. No disclosure to model providers for training purposes, no learning from your content.
How and when is data deleted?+
According to a fixed deletion concept per project phase, and earlier on request. Only what the task requires is processed.
How do you respond to a security incident?+
With fixed response times: 4 hours for critical matters, 8 business hours in normal operation. Maintenance windows are announced at least 48 hours in advance.
What happens to our data and configurations at the end?+
No lock-in: the configurations of your AI employees belong to you and can be exported in full to JSON, CSV and Markdown. After that, the deletion concept applies.
Privacy contact
datenschutz@scoreprise.ai
