AI Security and Compliance: Our Hosting Guarantees
At MarketerZ, AI security and compliance are not optional extras: they are concrete guarantees. Your data stays your data: encrypted, and never used to train a third-party model. This page lays out, without the sales pitch, what your IT and security team needs to know.
Your Data Never Trains a Third-Party Model
This is our first commitment, no exceptions. The conversations, documents, and data you share with MarketerZ remain your information asset: they are never reused to train a third-party AI model, and never shared with other clients.
Your data serves one purpose: running your own solution. Answering your users, analyzing your documents, feeding your knowledge base. Nothing else.
- Data isolation: each client has its own dedicated data environment.
- Conversation anonymization where relevant for quality control.
- No resale or sharing of data with commercial third parties.
AI Security and Compliance: Encryption and Access Control
Technical security protects your data at every step, from collection to storage. We encrypt sensitive data and strictly limit who can access it, both internally and on your side.
In practice:
- Encryption of sensitive data, in transit and at rest.
- Access control through authentication keys for every admin interface (dashboard, API).
- Activity logging on admin interfaces, useful for audits.
- Regular backups of your data, with a documented restore procedure.
These principles apply to a virtual assistant as much as to an enterprise AI agent, which handles more sensitive documents such as contracts, invoices, and supporting evidence.
Hosting Your Way: Cloud or Your Own Servers
You decide where your data lives. No hosting model is forced on you by default: you choose based on your internal constraints and your own security policy.
Two options are available:
- Cloud hosting, with European infrastructure prioritized when available.
- On-premise hosting, on your own servers, through Docker Compose containers your technical team can inspect and operate.
For organizations with stricter requirements, a fully local mode is possible: AI models run entirely on your own infrastructure, with no calls to an external service. That is the option chosen for the claims-analysis agent deployed at HomeAssur, backed by a dedicated data loss prevention (DLP) policy.
An Open, Documented Stack
We do not build our solutions on a proprietary black box. You know what is running, which components power it, and you are never locked into a single vendor.
For enterprise AI agents, the technical stack is open source and documented: LangGraph for orchestration, PostgreSQL with its pgvector extension for storage and document search, and FastAPI for the interfaces. Language models are your choice too: the Mistral API, or models run locally through Ollama, with no mandatory dependency on a cloud service.
This openness makes security audits easier, keeps your options open for the future, and simplifies integration with your existing systems, including older applications.
GDPR and AI Act Compliance
Your regulatory obligations are ours too. Every solution is designed with the General Data Protection Regulation (GDPR) in mind and, for advanced use cases, the European AI Act.
On the GDPR side, we rely on clear legal grounds for each processing activity, on the encryption and access controls described above, and on retention periods limited to what is necessary.
On the AI Act side, our AI consulting work includes classifying the risk level of your use case and identifying the transparency obligations that come with it. For the HomeAssur claims-analysis agent, that assessment concluded the use case is not classified as high-risk, with transparency obligations addressed from the design stage.
Traceability: Every Answer Can Be Justified
An AI answer that cannot be explained is not usable in a business setting. Our solutions are built so that every answer, every analysis, can be traced back to its source.
For a virtual assistant, that means answers draw on the validated content of your knowledge base, with a handoff to a human as soon as information is missing. For an enterprise AI agent, traceability goes further: every analysis cites the clauses or documents it relied on, and the conversation history stays available case by case.
This traceability benefits your teams directly: it documents a decision, supports quality control or an audit, and is a reminder that the final decision always stays with a human.
Automated Evaluations Before Every Production Release
Enterprise AI does not go live without being tested on real cases first. Before every deployment or update, we evaluate the solution against reference cases (golden cases) that represent your most frequent and most sensitive scenarios.
These evaluations check the quality and consistency of the answers before they reach your users or your team. This is the method that governs each production release of the HomeAssur claims-analysis agent, live since August 2026.
This discipline builds on the AI consulting approach we apply from the initial audit onward: it is easier to prevent errors than to fix them afterward.
Frequently asked questions
No, never. Your data is used for one purpose only: running your own solution. It is never reused to train a third-party model, and never shared with other clients.
Yes. On-premise hosting is available through Docker Compose, on your own infrastructure. A fully local mode is even possible for organizations that require it, with no calls to an external service.
Our AI consulting work classifies the risk level of your use case and identifies the transparency obligations that apply. For the HomeAssur claims-analysis agent, that assessment concluded the use case is not classified as high-risk.
Access to admin interfaces is protected by authentication, and activity there is logged. Internally, access to your data is limited to the people working on your solution.
Ask Your Technical Questions
Does your IT or security team have specific questions about hosting, security, or compliance? Let's talk directly, no sales pitch.
Book a call