[ Trust ]

WHAT WE DO
WITH
YOUR DATA.

CERVOX brings together three activities with different architectures. A single sentence about “our servers” would therefore be false for at least one of them. This page describes the actual mechanisms, activity by activity, and what we do not guarantee.

[ 01 · CERVOX SaaS ]

THE OPERATIONAL
SOFTWARE.

The SaaS processes your company’s management data, its documents and its connections to your business tools.

Hosting

SaaS data is hosted in France, with OVH. Encryption in transit (TLS 1.3) and at rest (AES-256).

Isolation

A non-modifiable organisation identifier, assigned at sign-up, and row-level filtering in the database, checked on every request and not just at login.

Bank connections

Read-only, through providers regulated by the ACPR (PSD2). No writes, no transfers, no changes. Encrypted tokens, automatic rotation.

Validation before action

Nothing is sent or triggered without your validation. Explicit confirmation for any irreversible action. History of actions and validations.

Revocation

Any connection to a third-party tool can be cut off immediately, from the application.

Voice processing

Voice transcription is performed on your device: the audio does not pass through our servers.

[ 02 · CERVOX Reasoning ]

THE VERIFICATION
LAYER.

The architecture described here is that of CERVOX Reasoning; it is set out because it differs from that of the SaaS and the difference matters.

Hosting

Reasoning infrastructure in the European Union, Paris region. A request issued in Paris may be processed in another supported European region: the data stays in the EU, without us claiming exclusively French processing.

Your documents

Storage encrypted at rest, separated by organisation, with deletion on request and confirmation.

Model training

No training on your data. This is a contractual guarantee from the infrastructure provider, which we pass on — we do not assert it on our own authority.

Your AI provider

The model that generates the text remains yours, under your own contract, with its own processing policy. Your credentials are stored encrypted and restricted to your organisation.

Isolation

Access boundaries per organisation, row-level filtering, separate storage prefixes. Designed to be demonstrable to an IT department, not just declared.

Audit log

Every verification is timestamped, attributed to an identified user and linked to a dated version of a document. Tamper-proof, exportable.

[ 03 · CERVOX Services ]

TECHNICAL
SERVICES.

For services, the infrastructure concerned is yours. We host nothing for you in this context.

Access to the scope

The credentials provided are restricted to the project and can be revoked at any time. We ask for the minimum necessary.

Confidentiality

The project, its code and its data are covered by a written confidentiality undertaking.

Ownership

The code is pushed to a repository you own. Intellectual property is transferred to you.

[ What we do not claim ]

THE LIMITS,
WRITTEN HERE.

These points are stated on this page rather than discovered during an audit.

  • CONSILIO SASU does not currently hold ISO 27001 certification. Our security posture relies on that of our infrastructure providers, which can be verified independently.
  • We do not use the word “sovereignty”: European hosting is not sovereignty, and not all of our technical dependencies are French.
  • Verification does not constitute regulatory compliance. The trace produced is an input into a governance framework, not a certificate.
  • The timestamped, attributed trace is not legally binding proof.
  • No mechanism makes a language model infallible. The aim is to make errors detectable, not to eliminate them.
SUBPROCESSORS AND GDPR

The list of subprocessors, processing purposes, retention periods and how to exercise your rights are set out in the privacy policy.

A SPECIFIC QUESTION

An IT department, a data protection officer or an auditor can write to us directly: contact@cervox.io.