Sovereignty and security
Sovereignty is not a promise. It’s an architecture.
You run security, compliance or governance for your organization. Here is where your data lives, who can access it and what the law actually requires of you.
Proof before words: this site is hosted in France, on OVHcloud. It sets no cookies. It loads no external resources. Its content security policy is strict. Check it in your browser’s tools.
Commitments
Four commitments, on every project.
Kept without exception. Verifiable from the first conversation.
- European hosting
- Your data is hosted with a provider based in France or the EU. It is our default on every project, never a point negotiated after the fact.
- AI installed locally
- A genuine option to install AI on your own servers, with no cloud involved. No data goes to a third party: there is no third party in the loop.
- Zero training
- Data you share with us never trains an AI model. Whichever tool the project uses.
- Signed GDPR agreement
- As soon as a project touches personal data, we sign a GDPR data processing agreement. It sets our instructions, our security duties and what happens to the data when the work ends.
Hosting
Two options, depending on your data.
The first: hosting with a provider based in France or the EU. The second: AI installed on your own servers, with no cloud at all. We choose with you, project by project.
Hosting and the AI model are two separate layers. Hosting is who runs the servers and where. The model is the AI software itself. A French host can run an American model. The reverse is true too.
ANSSI’s SecNumCloud qualification shows the difference. It qualifies hosting providers and infrastructure offerings, not AI models. No major model vendor offers a SecNumCloud-qualified API today. On every project, we tell you which host we use.
Security
Useful agents, kept in check.
An agent that acts on your tools, inbox or calendar saves time. It can also get things wrong, or be misused. In April 2026, CERT-FR, France’s government CERT, advised against autonomous agents not yet proven secure. We don’t sell autonomy: it is a means, kept in check.
Every agent gets only the access its task requires. Never your entire toolset by default.
Every automation is tested on your real data before going further. Moving it to production comes with secured access and secured data.
You keep control of the decisions that matter.
Legal framework
What the law actually requires.
GDPR
As soon as a project touches personal data, we sign a data processing agreement under Article 28 of the GDPR. It sets our instructions in writing, our security duties and what happens to your data when the work ends: deletion or return, your choice.
AI Act
Since July 27, 2026, Article 4 asks you to take measures to develop your teams’ AI literacy. It is an obligation of means: nobody has to guarantee a precise level for each person. Our training addresses it directly.
Obligations for high-risk systems are now expected in late 2027 and 2028. That timeline has already moved once. Acting early remains the best way to avoid the rush.
Extraterritoriality
The US CLOUD Act lets American authorities access data held by a provider under their jurisdiction, even when it is stored in Europe. What counts is the provider, not the server’s country.
Transfers to the United States remain covered by a European adequacy framework in force. We do not claim they are unlawful. We choose not to depend on that debate: a European host outside US jurisdiction, or AI installed on your premises, removes the question.
Questions
What your teams will ask.
- Why a French or European host?
- US law can reach a provider under its jurisdiction, even with servers in Europe. Transfers to the US remain lawful today. We would rather remove the question than answer it after the fact.
- What does SecNumCloud change for us?
- It qualifies hosting providers, not AI models. It covers the infrastructure: who hosts, how, with what guarantees. Choosing the AI model is a separate question.
- Can we use GPT, Gemini or Claude?
- Yes, if you wish. Professional plans from major vendors exclude training on your data by default. For the most sensitive data, we install open-weight models on your premises.
- Can your agents act on their own in our tools?
- Every agent gets only the access its task requires. Every automation is tested on your real data before production. You keep control of the decisions that matter.
- What does the AI Act change for our organization?
- Article 4 asks you to take measures to develop your teams’ AI literacy. It is an obligation of means, not of result. Obligations for high-risk systems arrive in late 2027 and 2028.
- What happens if we stop working with Toundra?
- Nothing stays locked in. The code, the access and the data are yours from delivery. Every project ends with a handover: your teams know how to keep what was built alive.
Contact
Let’s talk about your constraints, plainly.
A security question, an audit to prepare, a brief to scope. It all starts with a complimentary introductory session, on site or remotely.