As of 26 May 2026

Compliance
and sovereignty.

This page states the platform's posture plainly: what is in place today, what is in preparation and where we deliberately are not yet. No marketing promises and no wall of certificates we do not hold.

1. GDPR: what is in place and how it is evidenced

Our own assessment, not an external audit. We do not put a percentage on it: nobody outside could recheck a figure like that. What follows are the points that actually matter.

A data processing agreement under Article 28 is provided on request as a customized template; the terms are set out on its own page.

  • Eight active sub-processors, documented, with four weeks' notice before any change, as Article 28(2) requires.
  • Operations in the EU: compute and backups at Hetzner in Germany, model inference at Modal Labs in Frankfurt.
  • Data subject rights under Articles 15 to 22: self-service export in the tenant workspace plus a documented deletion matrix.
  • A data protection impact assessment under Article 35 exists for analytics; every new AI feature gets its own before it goes live.

2. EU AI Act: which duties apply and how they are met

Risk classification is predominantly minimal to limited, with individual workflows carrying the Article 50 transparency obligation.

SIMO GmbH is both: provider of the platform and deployer of third-party general-purpose models, namely Apertus 8B and the Mistral family.

  • The Article 50 transparency obligation is live: every answer is marked as AI-generated through a dedicated response header and a visible notice.
  • Model cards for Apertus 8B and the Mistral family, with provider, license, knowledge cutoff and usage limits.
  • Every model call is logged for thirty days with model ID, tenant hash, token count and response hash.
  • No high-risk system: no feature falls under Annex III today, so no biometric scoring, no candidate screening, no education ranking.

3. ISO/IEC 27001: in preparation

Work on Annex A is under way and some measures are still outstanding. The certification audit is planned for 2027; there is no certificate today.

Asset inventory, risk register, statement of applicability and incident response are being built out; document control runs through the repository.

Hetzner, who runs the infrastructure, is certified to ISO/IEC 27001. At that layer the benefit already applies.

4. BSI C5: preparation from Q4 2026

Mapping the C5:2020 controls onto existing measures is under way, starting with operations, identity management and key management.

No attestation has been issued to date.

5. Accessibility: partially compliant

Partially compliant with WCAG 2.2 at level AA and with EN 301 549 V3.2.1.

The statement of accessibility under section 14 of the German Accessibility Strengthening Act is published. A bilingual VPAT 2.5 Rev INT serves as the detail report and is issued on request via [email protected].

6. Schrems II and third-country transfers

The transfer impact assessment methodology is documented; the EU standard contractual clauses 2021/914 are in place for every US sub-processor wherever US processing occurs.

The default path is processing inside the EU. A transfer to the United States happens only when a tenant deliberately switches on the relevant connector, such as Tavily, Stripe or Microsoft Graph.

Stripe and Microsoft are certified under the EU-US Data Privacy Framework.

7. Data sovereignty: where everything lives

Data types, storage locations and encryption
Storage locationEncryption
Tenant databases (PostgreSQL)Hetzner, GermanyTLS in transit, LUKS at rest, column encryption for secrets with a rotating master key
Backups, daily, thirty daysHetzner Storage Box, GermanyAES-256 on a separate key path
Language model prompts and responsesModal Labs, FrankfurtTLS in transit, no retention at the model backend
Uploaded filesHetzner and Cloudflare R2 in EU bucketsTLS in transit, AES-256 at rest
Authentication secretsHetzner, GermanyArgon2id for passwords, master key held apart from the signing key
Payment dataStripe, EU and United States, DPF certifiedPCI-DSS level 1 at Stripe
Support ticketsHetzner, GermanyTLS in transit, LUKS at rest

8. Sub-processors: all eight of them

Role, region and contractual basis per provider. Existing customers are told about any change by email four weeks in advance, as Article 28(2) requires.

Active sub-processors as of 26 May 2026
RoleRegionSafeguard
Hetzner Online GmbHServers, storage, backupsGermanyProcessing agreement, ISO 27001
Cloudflare, Inc.DDoS mitigation, firewall, DNS, tunnelGlobal, EU-frontedProcessing agreement, EU standard contractual clauses, ISO 27001
Modal Labs, Inc.Compute for language modelsEU (Frankfurt)Processing agreement, EU standard contractual clauses, no retention
Stripe, Inc.Payment processingEU and United StatesProcessing agreement, EU standard contractual clauses, EU-US Data Privacy Framework
Tavily, Inc.Web search, only on tenant opt-inUnited StatesProcessing agreement, EU standard contractual clauses
Microsoft CorporationMicrosoft 365 connector, only on tenant opt-inEU at the tenant's choiceProcessing agreement, EU standard contractual clauses, EU-US Data Privacy Framework
GitHub, Inc.Source code hosting, no tenant dataUnited StatesProcessing agreement, EU-US Data Privacy Framework
GitGuardian, Inc.Secret scanning, no tenant dataEUProcessing agreement

9. Certificates: only what genuinely exists

This section lists what we actually hold. External audit certificates are not among them yet. The slots stay visible as an honest signal.

  • ISO/IEC 27001: targeted for 2027.
  • BSI C5: preparation from the fourth quarter of 2026.
  • TISAX: on request.

10. Contact and requests

For compliance inquiries, obtaining the processing agreement, vendor reviews or auditor access.

Postal address: SIMO GmbH, attn. Compliance, Würzburger Straße 152, 63743 Aschaffenburg, Germany.

This page is reviewed at least quarterly, and additionally whenever the platform changes materially.