WHAT WE DO
WITH
YOUR DATA.
CERVOX brings together three activities with different architectures. A single sentence about “our servers” would therefore be false for at least one of them. This page describes the actual mechanisms, activity by activity, and what we do not guarantee.
THE OPERATIONAL
SOFTWARE.
The SaaS processes your company’s management data, its documents and its connections to your business tools.
Hosting
SaaS data is hosted in France, with OVH. Encryption in transit (TLS 1.3) and at rest (AES-256).
Isolation
A non-modifiable organisation identifier, assigned at sign-up, and row-level filtering in the database, checked on every request and not just at login.
Bank connections
Read-only, through providers regulated by the ACPR (PSD2). No writes, no transfers, no changes. Encrypted tokens, automatic rotation.
Validation before action
Nothing is sent or triggered without your validation. Explicit confirmation for any irreversible action. History of actions and validations.
Revocation
Any connection to a third-party tool can be cut off immediately, from the application.
Voice processing
Voice transcription is performed on your device: the audio does not pass through our servers.
THE VERIFICATION
LAYER.
The architecture described here is that of CERVOX Reasoning; it is set out because it differs from that of the SaaS and the difference matters.
Hosting
Reasoning infrastructure in the European Union, Paris region. A request issued in Paris may be processed in another supported European region: the data stays in the EU, without us claiming exclusively French processing.
Your documents
Storage encrypted at rest, separated by organisation, with deletion on request and confirmation.
Model training
No training on your data. This is a contractual guarantee from the infrastructure provider, which we pass on — we do not assert it on our own authority.
Your AI provider
The model that generates the text remains yours, under your own contract, with its own processing policy. Your credentials are stored encrypted and restricted to your organisation.
Isolation
Access boundaries per organisation, row-level filtering, separate storage prefixes. Designed to be demonstrable to an IT department, not just declared.
Audit log
Every verification is timestamped, attributed to an identified user and linked to a dated version of a document. Tamper-proof, exportable.
TECHNICAL
SERVICES.
For services, the infrastructure concerned is yours. We host nothing for you in this context.
Access to the scope
The credentials provided are restricted to the project and can be revoked at any time. We ask for the minimum necessary.
Confidentiality
The project, its code and its data are covered by a written confidentiality undertaking.
Ownership
The code is pushed to a repository you own. Intellectual property is transferred to you.
THE LIMITS,
WRITTEN HERE.
These points are stated on this page rather than discovered during an audit.
- CONSILIO SASU does not currently hold ISO 27001 certification. Our security posture relies on that of our infrastructure providers, which can be verified independently.
- We do not use the word “sovereignty”: European hosting is not sovereignty, and not all of our technical dependencies are French.
- Verification does not constitute regulatory compliance. The trace produced is an input into a governance framework, not a certificate.
- The timestamped, attributed trace is not legally binding proof.
- No mechanism makes a language model infallible. The aim is to make errors detectable, not to eliminate them.
The list of subprocessors, processing purposes, retention periods and how to exercise your rights are set out in the privacy policy.
A SPECIFIC QUESTIONAn IT department, a data protection officer or an auditor can write to us directly: contact@cervox.io.
