We protect the most sensitive data in the building.
Your data stays in the EU. Full stop.
Every document, every database record and every login lives in the EU (Frankfurt) — and every step that touches your data, from analysis to text recognition to search, runs in EU regions too. Non-EU providers are switched off by default. If an EU service ever declines a request, we fail over to another EU route — never to a non-EU one. Your documents never leave our EU environment; the background jobs that process them carry only reference IDs, never the contents.
Your documents never train a model.
The one that matters most, so we'll be blunt: your matter data is never used to train any model — not a provider's, and not ours. Analysis runs statelessly, provider-side logging is off, and zero-retention terms are in force across the board. There is no "help us improve the product with your data" toggle, because there shouldn't be one. Your evidence answers your question — then it's gone from the model layer.
Isolation you can't argue with.
Every record is walled off to your firm by row-level security enforced in the database itself — not application code a bug could slip past. Permissions live in a separate table from user accounts, so no one can quietly escalate their own access. The single privileged key that can cross those boundaries runs only on trusted server paths and is never reachable from a browser. One firm cannot see another's data — by construction, not by policy.
Where it matters, we don't trust the model.
The safeguards that protect your clients don't depend on an AI behaving correctly. The identifiers we mask are caught by deterministic rules, not a model's best guess. Access is enforced by the database, not a prompt. Cited quotes are checked against the source page by exact text match, with no model grading its own work. AI does the heavy lifting; deterministic systems hold the line.
Encrypted end to end.
Everything is encrypted in transit with TLS 1.2+ and at rest with AES-256 — documents, extracted text, database and audit log alike.
Two-factor for everyone.
Two-factor authentication is mandatory: every user enrols a second factor before they can use Denua. No anonymous access, no exceptions.
Share a chronology without exposing your client.
Before anything goes to counsel or an expert, one click pseudonymises it. The identifiers that actually endanger a client — NHS numbers (validated to their check digit), dates of birth, postcodes and addresses, emails, phone numbers and case references — are masked by deterministic rules that don't rely on a model spotting them. The key to reverse the redaction stays with your firm; we never store it. And we log only how many items were masked — never the items themselves.
Delete means delete — and we give you the receipt.
Delete a matter and the document files are purged immediately; everything else is hard-deleted after 30 days, cascading through every record it touched. You receive a signed deletion certificate — a manifest of what was removed, with SHA-256 hashes — as proof it's gone. Cancel your subscription and the same 30-day countdown begins.
A record you could hand to a regulator.
Every consequential action — sign-ins, exports, sign-offs, deletions — is written to an audit trail and kept for 12 months. It's written by the system and cannot be edited by users. And when a lawyer signs off a matter, we hash the exact state they approved (SHA-256), so any later change is detectable against what was actually signed. Not "trust us" — provable.
Governance built for due diligence.
You are the data controller; Denua is your processor, acting only on your instructions. EU Standard Contractual Clauses are in force with every sub-processor — the full list is available on request, with 30 days' notice of any change. A confirmed personal-data breach is reported to you within 72 hours. Data-subject requests are answered within 30 days.
Certifications, stated honestly.
We don't display badges we haven't earned. Denua has been built to ISO 27001 alignment from day one, and ISO 27001 and SOC 2 Type II audits are underway; we'll share the reports the moment they're issued. Until then, we'd rather tell you exactly where we stand than imply a certificate we don't hold.
Your risk committee will have questions. We have answers.
A security overview, the sub-processor list and our data-processing agreement are ready to send. Contact your client advisor for more information.
Our security, at a glance
EU (Frankfurt) — data at rest and in processing
AES-256 at rest · TLS 1.2+ in transit
Zero training · zero retention — your data never trains any model
Mandatory two-factor authentication for every user
Per-firm isolation via database row-level security
One-click de-identification — the re-identification key stays with you
Immediate file purge · 30-day hard delete · signed deletion certificate
12-month immutable audit trail · tamper-evident sign-off
UK GDPR processor · EU SCCs · 72-hour breach notice · 30-day DSAR SLA
ISO 27001 & SOC 2 Type II — audits in progress; reports on request
Security isn't a page we bolted on. It's the architecture.
Trust that when you use Denua, your client's data is secure.
