Confidentiality — question #1, treated as #1

Your procurement data, processed within the perimeter agreed with you.

It is every buyer's legitimate objection to AI. Yxalo's answer: three deployment levels, chosen according to the sensitivity of your data. The detailed architecture is documented and handed to your CISO or DPO.

Discuss your case 45 minutes, no commitment — bring your constraints.
The principle, at every level

What is not negotiable.

Your data is processed solely within the technical and contractual perimeter agreed with you. It is never used to train the models. Subprocessors, locations, retention periods and reversibility conditions are documented before deployment.

The three levels

You choose where your data lives.

L1 · Professional standard

Enterprise environment, with no training on your data.

L2 · European

Processing and storage in the European Union.

L3 · Sovereign

French qualified infrastructure for the most sensitive files.

Deployment is possible on a SecNumCloud-qualified cloud infrastructure, depending on the project's scope and requirements. The right reflex: start at the level that matches your actual data, not at the maximum on principle.

The detailed architecture (subprocessors, locations, retention, reversibility) is documented and handed to your CISO or DPO as part of a deployment.

Your questions

The questions we get. The honest answers.

My teams already use free AI tools. What is the problem?

Consumer versions may use conversations to improve their models, and your prices circulate there with no framework or traceability. Moving to a professional offering changes the contract: zero training, controlled perimeter — for a cost far below the risk.

What data is the first demonstration run on?

The first demonstration runs on fictional, public or previously anonymised data. Real files are processed only after contractual scoping and the choice of the appropriate confidentiality level.

Who, on our side, sees what?

Each user has their own account and conversations. Assistants are enabled company by company and user by user. You keep control of the rights — and your content is not our data.

Are we locked into one level forever?

No. The level is chosen per perimeter according to the sensitivity of your data. The tool stays the same for your teams.

The first step

Bring your constraints. We answer precisely.

CISO, DPO, management: bring your requirements — the detailed architecture that answers them is documented and handed to you as part of a deployment.