Isolated instance
A client instance is the isolation boundary. The concrete databases, storage regions and access routes are documented before productive processing. Only named people have access to your instance.
This page separates three things: what the architecture provides for, what is committed contractually and what is fixed per deployment. A blanket statement is settled in five minutes in a security review.
A client instance is the isolation boundary. The concrete databases, storage regions and access routes are documented before productive processing. Only named people have access to your instance.
Data regions and subprocessors are confirmed in writing per instance before productive processing. The security review contains the current processing chain, including purpose, region and any third-country transfer.
supakraft does not train a model of its own on client data. For connected model providers, the data processing terms agreed for the respective instance apply. Which providers those are is stated in the data processing agreement.
Before external use, a verified eligible person approves the exact stored output. A generation is not an approval, and an approval is not yet a delivery.
A governed run records which execution basis applied, which checks ran, how they resolved and who approved. The audit trail can be exported.
supakraft is not a compliance badge. Governance functions such as versioned evidence, checks and human approvals can support internal control processes. Which legal obligations apply depends on the concrete use.
A technical export of brand truth uses the open OBDS format. Retention, deletion and the remaining audit evidence are defined per deployment. The concrete obligations sit in the client contract and the data processing agreement.
We answer questions from procurement or IT security directly. hello@supakraft.ai