Trust

Security

An honest account of how Svalv handles data, what we've secured, and what's on our roadmap.

Architecture & isolation

Svalv deploys AI models inside your infrastructure — your GPUs, your network, your jurisdiction. The models, inference engine, and data pipeline run entirely within your perimeter. Svalv's operational layer connects only to deliver configuration updates, collect health telemetry, and generate compliance evidence — never to access your prompts, documents, or inference outputs.

Data handling

  • Customer AI data: never reaches Svalv. Prompts, documents, embeddings, and inference outputs stay inside your infrastructure at all times.
  • Site & booking data: form submissions (name, email, company, role) are processed by Netlify Forms with data stored in EU-hosted infrastructure.
  • Analytics: Plausible Analytics (cookieless, EU-hosted). No personal data collected. No consent banner required.

Encryption

All data in transit: TLS 1.3. Deployment configurations and evidence artifacts: encrypted at rest with AES-256. Customer-side model weights and inference data: encrypted per your infrastructure standards — Svalv does not manage customer-side encryption keys.

Access control

Svalv team access to operational systems requires multi-factor authentication and is scoped to the minimum necessary for deployment and support. No Svalv employee has access to customer inference data, prompts, or documents.

Compliance status

Svalv is pre-certification. We are an early-stage company and have not yet completed third-party audits.

Roadmap

  • SOC 2 Type I — target: 2027
  • ISO 27001 — target: 2027–2028
  • ISO 42001 (AI management) — target: 2028

These are targets, not commitments. We will update this page as certifications progress.

Bring sovereign AI inside your walls.

Book a call or join the pilot. We'll map your infrastructure and models to DORA and EU AI Act requirements — and the evidence to prove it.