SECURITY · Built for legal and compliance.

Your most sensitive data,
safe by design.

Zaphir is built on a non-negotiable principle: your data stays in Europe. Contracts, policies, matters and correspondence are hosted in EU data centres with end-to-end encryption, zero retention and zero training. GDPR compliance by architecture.

Zaphir

DEPLOYMENT

Two versions. Same AI.

In both versions your data stays in your perimeter. The difference is where the AI inference runs: on a dedicated machine we host in EU data centers, or on your own hardware.

01 · ON-PREM

Zaphir On-Prem

A machine dedicated to you, hosted by us in EU data centers. AI inference in EU data centers (zero-retention, EU residency). Setup in hours, nothing to manage.

The GDPR default for firms and SMEs.

  • A machine dedicated to you, EU data centers
  • Zero-retention inference, end-to-end encryption
  • Setup in hours, fully managed

02 · SOVRANA

Zaphir Sovereign

Same AI, but everything stays at your premises. Both the AI model and the software run on your local hardware · no external calls, no internet connection required. The whole system lives inside your walls.

› On-premise hardware (default)

AI model and software both installed on your NVIDIA GPUs. Air-gappable, zero external calls. Everything lives in your office.

› Private cloud (optional)

If you prefer, we deploy on AWS / Azure / GCP EU under your contract, or in a dedicated VPC we configure for you.

For regulated organisations or anyone who wants nothing leaving the building.

Sovereign details
Hoplo NVIDIA Partner Connect

NVIDIA TECHNOLOGY PARTNER

Reference architectures and deployment expertise on NVIDIA infrastructure across all three deployment models, from EU cloud to fully on-premise.

CERTIFIED & COMPLIANT

Aligned with the security and privacy standards required by legal and compliance workflows.

GDPR

Native support for the European regulation. DPA available, data-subject rights supported and processing activities documented.

EU AI Act

Ready for the European AI regulation: model classification, technical register, transparency on system origin, and enterprise-grade internal governance.

EU data centers

Exclusive hosting within the European Union via certified hyperscale providers. No extra-EU transfers of your confidential files, no third-country jurisdiction.

End-to-end encryption

TLS 1.3 in transit and AES-256 at rest across legal and compliance documents. Key management with periodic rotation and separation of duties.

STORAGE & PRIVACY

Storage and privacy by construction.

EU-only hosting

Inference, indexing and storage of contracts, policies and matters happen inside the European perimeter. No data crosses non-EU jurisdictions.

Zero retention

Queries and processed documents are not retained beyond the time required for analysis. No residual copies and no opaque caching.

Zero training on your data

Contracts, policies, matter files and correspondence are never used to train models. Inference stays in the agreed EU or on-premise perimeter.

ENTERPRISE SECURITY

Enterprise-grade security.

Zero-trust architecture

Every request is authenticated and authorised. No internal service is reachable without verified identity and valid context.

End-to-end encryption

TLS 1.3 across all communications, AES-256 at rest. Keys are managed with periodic rotation and separation of duties.

Complete audit trail

Every operation, login, query, view, download, sharing a memo, is recorded in immutable, timestamped logs, exportable to corporate SIEMs.

Access control & SSO

SSO/SAML, MFA and IdP integration. Roles, groups, matters and information barriers use granular permissions.

FAQ

Frequently asked.

The architectural choices that protect legal and compliance data at every level.

Customer data includes every document, email, query or metadata item that passes through Zaphir: contracts, policies, matter files, regulatory sources, search history and access logs. All are treated as confidential and remain in the agreed perimeter.

Serious about security?

Book a demo