# ISMS Copilot Trust Center > Security, privacy, and compliance information for ISMS Copilot — the AI-powered ISO 27001 compliance platform. ## Overview ISMS Copilot is an AI-powered platform that helps organizations build and maintain ISO 27001 Information Security Management Systems. This trust center provides transparency about how we handle data. ## Compliance - GDPR compliant (registered with CNIL, France) - Data Processing Agreement (DPA) available covering GDPR Article 28 - EU-Only mode available via Advanced Data Protection - Infrastructure providers (AWS, Supabase) are SOC 2 Type II attested ## EU AI Act transparency - Public statement: https://trust.ismscopilot.com/en/ai-transparency - Current assessment: not prohibited (Art. 5); not Annex III high-risk for intended advisory purpose; Article 50 transparency applies - Not a regulator certification or ISO 42001 certificate - Art. 50(2) machine-readable marking of generated document exports: in progress (target 2 Dec 2026 transitional period for systems already on market) ## Data Residency - Database and file storage: EU (Frankfurt, Germany) — always - Default AI processing: Anthropic Claude (direct routing, US, SCCs); OpenRouter aggregator (US) routing to one of four allowlisted underlying providers — Inceptron, DeepInfra, Cerebras, or Google Vertex (each US, per-provider SCCs; Google Vertex additionally covered by EU-US Data Privacy Framework). Routing is determined per request by plan and Advanced Data Protection setting; see DPA §2.4 for the full matrix. - Advanced Data Protection mode: Mistral AI (EU Frankfurt), zero retention, no US data transfers — available on any plan - Content moderation: Mistral AI (EU) in all modes (regardless of ADP) - AI failover: Mistral AI (EU) - OpenRouter account-level controls (applied to every OR-routed request): mandatory Zero Data Retention, training disallowed, closed 4-provider allowlist, PRC-jurisdiction blocklist (Alibaba Cloud International, Baidu Qianfan, DeepSeek, Moonshot AI, Xiaomi, Z.AI) ## Security - Encryption in transit: TLS 1.3 - Encryption at rest: AES-256 - Row-level security at database level - Built-in PII redaction before AI processing - User data is never used for AI model training - No training under Anthropic's and Mistral's commercial API terms; OpenRouter "Training Disallowed" enforced at the account level for all four allowlisted underlying providers ## Subprocessors ISMS Copilot uses the following Active sub-processors: - Supabase (EU Frankfurt) — Database & Authentication - AWS (EU Frankfurt) — Infrastructure - Anthropic Claude (US) — AI Processing (default routing, ADP off), 30-day abuse-monitoring cache only (not training) - OpenRouter (US) — Routing aggregator (ADP off) routing to the four allowlisted underlying providers below; mandatory Zero Data Retention enforced at account level - Inceptron (US) — OpenRouter underlying provider, zero retention - DeepInfra (US) — OpenRouter underlying provider, zero retention - Cerebras (US) — OpenRouter underlying provider, zero retention - Google Vertex (US) — OpenRouter underlying provider, zero retention; SCCs + EU-US Data Privacy Framework - Mistral AI (EU Frankfurt) — AI Processing (ADP), content moderation, failover, conversation summaries; zero retention - Fly.io (EU) — Chat API Service, 7-day logs - ConvertAPI (EU Frankfurt) — Document Conversion (ISO 27001:2022, signed DPA), zero retention (in-memory only) - Stripe (US) — Payment Processing (PCI DSS Level 1) - PostHog (EU Frankfurt) — Product Analytics - Sentry (Germany) — Error Tracking, 90-day retention (PII-scrubbed, no IP stored) - Vercel (EU Frankfurt) — Web Hosting (cookieless analytics) - SendGrid (US) — Legal Update Emails - Kit/ConvertKit (US) — Onboarding & Product Emails 30 days advance notice is provided before adding new Active sub-processors. ### Customer-Activated Integrations These sub-processors only become active for a Customer's data when that Customer's organization owner explicitly installs an optional integration in-product. The 30-day advance-notification rule does not apply because no data flows until the Customer takes an explicit activation step. - Slack Technologies, Inc. (US) — heygrc bot, install gated to paid-organization owners only; uninstall hard-deletes all integration records ### Reserved Sub-processors (code paths exist but not invoked from any user-facing flow) - OpenAI, xAI (Grok), Google Gemini — see DPA §2.4 for the full list and activation policy ## Legal Documents - Data Processing Agreement: https://trust.ismscopilot.com/dpa - Privacy Policy: https://trust.ismscopilot.com/privacy-policy - Terms of Service: https://trust.ismscopilot.com/terms - Register of Processing Activities: https://trust.ismscopilot.com/ropa ## Contact - Website: https://ismscopilot.com - Docs: https://docs.ismscopilot.com/docs - Status Page: https://status.ismscopilot.com