Skip to content
Security & Compliance

Adopt AI without losing control.

neuland.ai HUB is designed for companies where security, data protection and regulation are core requirements. Certified, audited and traceable.

All certificates and contracts are available for download in the Trust Center.

Audited & documented

  • ISO 27001Information security
  • ISO 9001Quality management
  • GDPRData protection
  • EU AI ActEU AI regulation
  • DORAOperational resilience
  • StBerGTax advisory
  • BRAOLawyers

Made for Germany

Built for complex business processes and regulated industries.

neuland.ai HUB meets common regulatory requirements from day one and is designed for highly regulated environments, for example under these frameworks. View evidence in the Trust Center

GDPR

European data protection standard, fully documented.

EU AI Act

Compliant with the EU AI Act, including high-risk applications.

BRAO

Suitable for law firms and mandates that require special confidentiality.

DORA

Supports the operational resilience requirements for financial service providers.

StBerG

For tax advisors and auditors: a separate supplementary agreement covers the requirements of the German Tax Advisory Act (StBerG).

Tenant isolation, audit logs, EU hosting

Your data stays in a protected environment. System access and events are logged in a traceable way.

Our standard

Security is verifiable.

VerifiableCertified, not promised.ISO 27001-certified information security management system, ISO 9001 quality management, verified compliance with GDPR, the EU AI Act and DORA, among others. All relevant evidence is publicly available in our Trust Center.
SovereignYour data, your decision.Operation in EU data centers or on-premises, depending on your security requirements. A multi-LLM approach with no dependence on a single provider. Developed in Cologne, operated to European standards.
TransparentListed in the DPA. Not in the fine print.Every subprocessor is named in the DPA, with no blanket clauses. Which ones are involved depends on the deployment model and your choice of connectors. You always know where your data is processed.

Regulated industries

Built for companies under regulatory supervision.

Select your industry for an overview of the requirements neuland.ai HUB meets.

neuland.ai HUB

  • Meets the requirements of the Federal Lawyers' Act (BRAO) for professional secrecy holders
  • Contractual protection through the BRAO addendum
  • End-to-end encryption and granular authorization concepts
  • EU hosting or on-premises operation, depending on your security requirements

neuland.ai HUB

  • Meets the professional requirements of the German Tax Advisory Act (StBerG)
  • Contractual protection through a supplementary agreement for professional secrecy holders
  • Role-based access control (RBAC) and the principle of least privilege
  • Fully disclosed processing chain with only two subprocessors

neuland.ai HUB

  • Meets professional regulations protecting confidential patient information
  • Data protection compliance under GDPR and BDSG
  • Technical and organizational measures based on an ISO 27001-certified ISMS
  • Operation in EU data centers or on-premises for maximum data sovereignty

neuland.ai HUB

  • Meets the requirements of the Digital Operational Resilience Act (DORA)
  • Contractual protection through a supplementary DORA agreement
  • ISO 27001-certified information security as the technical and organizational foundation
  • Transparent, short processing chain to support your third-party risk management

Governance

AI is not the problem. Governance is.

Where neuland.ai HUB runs, which models it uses and which subprocessors are involved.

AI is being used anyway. What matters is whether it happens in a governed, controlled and auditable way within a secure environment.

  • EU hosting or on-premisesDepending on your security requirements, you can run neuland.ai HUB on European-regulated infrastructure or entirely in your own environment.
  • Multi-LLM without vendor lock-inneuland.ai HUB avoids strategic dependence on any single model or vendor. Models can be swapped without fundamentally changing the platform.
  • Developed in GermanyMore than 50 people in Cologne develop neuland.ai HUB. It runs on systems subject to European regulation.

Technical and organizational measures

Four layers of control. One closed system.

Our TOMs cover every layer at which data must be protected. The measures are documented and available in the Trust Center.

Physical access controlServer roomsPhysical protection of the server rooms, biometric access control, 24/7 monitoring by security staff.
System access controlMFA, RBACMulti-factor authentication, role-based access control (RBAC), automatic locking of inactive accounts.
Data access controlLeast privilegeGranular authorization concepts, principle of least privilege, regular access reviews.
Transfer controlTLS 1.3, VPNEnd-to-end encryption, TLS 1.3 for all web connections, VPN connections for remote access.

For your review

Everything your legal and data protection teams need, at a glance.

All contracts, agreements and certificates are available for direct download in the Trust Center.

Contract

Data processing agreement (DPA)

Basis for data processing under Art. 28 GDPR

Contract

SaaS terms and conditions

Contractual framework for platform operation

Agreement

DORA addendum

For companies in the financial sector

Agreement

BRAO addendum

For lawyers and professional secrecy holders

Agreement

Microsoft supplementary agreement

Provisions on subprocessors

Evidence

Data protection compliance

Overview of GDPR and BDSG compliance

Certificate

ISO 27001 certificate

Information security management system

Certificate

ISO 9001 certificate

Quality management system

FAQ

What data protection, internal audit and works councils want to know.

See how companies put AI to productive use: practical examples from real use cases.

  • With ready-made documents: the DPA under Art. 28 GDPR with the subprocessors, documented TOMs, the ISO 27001 and ISO 9001 certificates, and supplementary agreements, including for DORA and BRAO, all in the Trust Center. The assessment is up to your organization.

Ready to start? The evidence is already in the Trust Center.

From AI strategy to a running platform: we show you the way. neuland.ai complies with GDPR, DORA and BRAO and is designed for secure use in regulated organizations.

Page footer