Trust center
Trust is documented.
Where the data lives, who can see it, how it is protected and what we sign: the answers a careful customer asks before starting — all on one page.
Personal data and GDPR
- Privacy by design and by default (art. 25 GDPR) in every project: minimization, mapped legal bases, defined retention.
- Data Processing Agreement (DPA) available on request where we act as processor.
- Complete, compliant notices: privacy policy with per-purpose legal bases and cookie policy following the Italian DPA's guidelines.
- No data selling, no use of customer data to train third-party models.
Where the data lives
- UEBB-managed cloud on Italian datacenters, or on-premise on your infrastructure: you choose, project by project.
- Air-gap option for environments that must never touch the internet: we have already done it, with LLMs and vision served on site.
- Non-EU sub-processors only where necessary and declared, with adequate safeguards (e.g. EU-US Data Privacy Framework).
Application security
- UEBB CyberSystem®: three-layer AES-256-GCM envelope encryption, one key per file, master-key rotation without re-encrypting.
- Personal recovery codes derived with Argon2id, TOTP two-step verification (RFC 6238), zero plaintext secrets.
- Immutable audit trail with 5-year retention on systems that require it.
- Sanitized inputs, security headers (HSTS, nosniff, frame-deny) and minimal exposed surface.
Operational security
- The same technologies we bring to customers protect us too: endpoints and network on the Sophos stack (Silver Partner), immutable backups and disaster recovery with Veeam (Cloud & Service Provider).
- Least-privilege access and separation of development, test and production environments.
- Regular updates and patching, monitored dependencies and security audits on our own website.
EU AI Act and governance
- Every AI system we deliver is born with proportionate risk classification, technical documentation, logging and human oversight.
- AI literacy (art. 4) and transparency towards users (art. 50) treated as project requirements, not attachments.
- AI system registry and impact assessments coordinated with GDPR (DPIA/FRIA) when needed.
Verifiable partnerships
- NVIDIA Inception Program for AI technologies.
- Sophos Silver Partner for cybersecurity.
- Veeam ProPartner (Cloud & Service Provider) for backup and data resilience.
- AWS, Microsoft Azure and Google Cloud Partner for cloud architectures.