Overview
Nordflak is built for organisations that need to know their data stays in Europe. Our security work rests on three principles: encryption of all data, European infrastructure with no non-European suppliers, and minimal access to data.
This page describes the technical and organisational measures we use to protect your data.
Encryption
Your data is stored encrypted on European servers, both at rest and in transit. Traffic between your client and the service is protected with modern TLS standards, and stored data is encrypted at disk level.
Encrypted at rest and in transit. Keys are managed in European infrastructure and rotated according to our internal procedure.
European infrastructure
All operations run on European servers within the EU/EEA. We use no non-European suppliers anywhere in our infrastructure, which means your data does not depend on rules or decisions outside Europe.
That is the core of Nordflak: if the cloud on the other side of the Atlantic shuts down, your business should keep working.
Access and permissions
We apply the principle of least privilege. Access to systems and data is granted only to those who need it for their work, and access can be traced.
- Strong authentication
- Sign-in is passwordless: you log in with a one-time code sent to your email and can add two-factor authentication via an authenticator app (TOTP). Administrators are required to use two-factor. Sign-in does not depend on Microsoft, Google or any other external identity platform.
- Role-based access
- Permissions are governed by role and reviewed on an ongoing basis.
- Traceability
- Access to sensitive systems is logged and can be reviewed after the fact. In addition, every AI call is logged in a tamper-evident log, where entries are cryptographically chained so that an entry cannot be altered or removed after the fact without it showing.
Operations and monitoring
The service is continuously monitored for anomalies and disruptions. Security logs are collected to detect and investigate suspicious activity.
We take regular, encrypted backups within the EU/EEA so that data can be restored when needed. Changes to production are made through reviewed and documented procedures.
Models and content
Nordflak uses the European Mistral models. Before your content is sent to the model, Swedish personal identity numbers, email addresses and phone numbers are automatically masked in the text, and uploaded files are run through a redaction that covers detected personal data in text and images. The content that is sent in is processed to deliver answers to you.
Content is stored encrypted and is subject to the same strict access controls as other customer data.
Incident management
We have procedures for detecting, handling and communicating security incidents. If a personal data breach occurs that requires it, we notify the supervisory authority within 72 hours and inform affected customers in accordance with the GDPR.
Report a vulnerability
Have you found a security flaw? We appreciate responsible reporting and give you time to report before anything is made public.