How we protect your data

You trust us with your company's financial data, and we know exactly how much that trust weighs. Here is the short version of how we keep your data safe. The full detail is ready for your security and legal teams whenever they want it.

Microsoft Azure · EEA

Your data does not leave the EU

Everything is stored and processed in Microsoft Azure data centres inside the European Economic Area. That includes all AI processing. Simple rule, no fine print.

ISO 27001 certified

Our information security management system is ISO 27001 certified and independently audited. We review it continuously, because a certificate is only worth something if you keep living up to it.

Locked down by default

All data is encrypted in transit. Access follows least privilege, with multi-factor authentication for everyone, including our own team.

Your data never trains AI

Your data is never used to train AI models and never touches public AI services. All AI runs inside our own Azure environment, and every AI action is logged, so you can always see what happened and why.

One sub-processor, no surprises

Exactly one: Microsoft Azure, for hosting and AI. If that ever changes, you hear it from us in writing 30 days in advance, with the right to object.

The paperwork is ready when you are

Behind this page sits the full contractual framework your legal team will want to see:

  • A GDPR Article 28 DPA with a dedicated AI annex, shared before you sign anything
  • Breach notification within 72 hours
  • On exit, your data is deleted or returned within 30 days
  • Audit rights on reasonable notice

Questions from your security or legal review? We are happy to share the full Data Processing Agreement, including the AI annex, and walk through our set-up with your team.

Contact us or read the NineAnts privacy policy.

Security | Automation Boutique