Trust, security and compliance | Flowstead

A new employee receives controlled access.

We take the same approach with digital colleagues. During onboarding, we gradually increase their autonomy under the supervision of your team and ours.

Six basic principles

Just as you would expect from a good employer, but for digital colleagues.

They operate in the EU

All data is stored and processed in European data centres.

They keep your data private

Your data is not used to train AI models. We put that in the contract.

They work only for you

Every organisation receives a technically isolated environment and its own knowledge layer.

They only see what they need

Access is role- and task-based: no more than the agreed process requires.

They maintain a full audit trail

Actions and exceptions are recorded, so you can always see what happened.

Your data remains portable

If you stop using Flowstead, you take all the data and knowledge your organisation has built with you.

Deployment

Choose how much infrastructure you want to control yourself.

Managed

Flowstead Cloud

Your private environment on European cloud infrastructure.

Fully managed by us, no maintenance for you
No dedicated hardware needed
Start affordably and scale when you want
Dedicated hardware

Flowstead Dedicated

Dedicated hardware running everything, including the AI models.

Nothing is shared, and nothing leaves your environment
No US cloud provider in the chain
Built for the strictest customer and supply-chain requirements
Regulatory framework

GDPR, the EU AI Act and NIS2: this is how we handle them.

GDPR

  • All data processed and stored within the EU
  • Data processing agreement included as standard
  • Audit trail supporting access and deletion requests
Request the data processing agreement

EU AI Act

From 2 August 2026.

  • Our applications fall outside the high-risk categories
  • Human oversight for every digital colleague
  • Built-in transparency: clear when AI is answering
Official EU AI Act guidance

NIS2 / Cybersecurity Act

From 15 August 2026.

  • Set up for supplier assessments in your supply chain
  • Data location, access and logging documented
  • Incident response process with fixed reporting deadlines
Government announcement
Frequently asked questions

For your technical review.

Within the EU, encrypted in transit and at rest. We document the chosen region and infrastructure before starting, both technically and contractually.

No. Not by Flowstead and, through our agreements with suppliers, not by model providers either. This is included in our data processing agreements.

That depends on the process, required quality and chosen deployment. We document the specific models and endpoints for each environment. In Flowstead Dedicated, models run on dedicated hardware without a public model API.

We connect with common ERP, email and accounting systems such as AFAS, Exact Online, SAP and Microsoft 365. Before starting, we determine exactly which secure connections your process needs.

Only authorised Flowstead engineers have access for management and support. Access is role-based, limited and logged.

Yes. It sets out roles, security arrangements, sub-processors, retention periods and how incidents are handled.

We return all data created during the engagement in a standard format. We then delete the environment according to the agreed procedure and confirm its removal.

The Dutch Cybersecurity Act comes into force on 15 August 2026 and implements NIS2. You must determine whether the law applies to your organisation. Flowstead supports supplier assessments with EU data location, limited access, logging and documented processing agreements.

The application determines the risk category and obligations. We assess this per process, build in human oversight and logging, and provide the required transparency. Flowstead does not build digital colleagues for recruiting, selecting or assessing employees.

Still have questions? Ask us directly.

We are happy to discuss your technical and contractual questions.