Security

What we commit to, and where the limits are.

Where your data is processed, what rooom AG commits to and where there are exceptions.

What sovereignty means in practice

EU data centres

Storage and AI processing in EU data centres; self-operated models may additionally run in Iceland or Norway (EEA). The exception is the optional web search (Brave, USA). The service providers involved are listed in the privacy policy.

ISO/IEC 27001:2022

rooom AG is certified under ISO/IEC 27001:2022 (certificate no. DE-IS-20260205).

GDPR processing agreement

You conclude a data processing agreement under Art. 28 GDPR with rooom AG. On request.

No training on your data

We do not use your inputs, documents or answers to train models.

AI labelling

Images and videos carry machine-readable metadata and an invisible watermark; speech output carries a machine-readable label. Under Art. 50 of the AI Act, on every plan.

A provider from Jena

rooom AG has been building software since 2016 that is also used by DAX companies. eNetworkers GmbH supports technical operations.

Open models, run by us

Many AI offerings with an EU label pass requests on to US model providers. SovrGPT works with open models that we run in EU data centres ourselves or have European partners run for us.

Typical AI platform

  • At its core a model from a US provider
  • "EU hosting" often means a relay server in front of the US API
  • The US provider sets model, price and availability

SovrGPT

  • Open models such as Gemma, Qwen and GLM
  • Processing in EU data centres, with each model showing whether we run it ourselves
  • Interchangeable models, no lock-in
  • No US model provider by default. Connect other providers with your own key if you need them.
Security and sovereignty | SovrGPT