GDPR
European data protection standard, fully documented.
neuland.ai HUB is designed for companies where security, data protection and regulation are core requirements. Certified, audited and traceable.
Audited & documented
Why it matters
Generative AI is already used in German companies, often without clear guidelines, keyword shadow AI. The question is no longer whether your teams use AI, but whether you can take responsibility for this use and steer it.
Made for Germany
neuland.ai HUB meets common regulatory requirements from day one and is designed for highly regulated environments, for example under these frameworks. View evidence in the Trust Center
European data protection standard, fully documented.
Compliant with the EU AI Act, including high-risk applications.
Suitable for law firms and mandates that require special confidentiality.
Supports the operational resilience requirements for financial service providers.
For tax advisors and auditors: a separate supplementary agreement covers the requirements of the German Tax Advisory Act (StBerG).
Your data stays in a protected environment. System access and events are logged in a traceable way.
Our standard
Regulated industries
Select your industry for an overview of the requirements neuland.ai HUB meets.
Your requirement
The BRAO obliges you to protect client confidentiality, especially when using technical service providers. An AI infrastructure that does not meet this requirement is not viable for your law firm.
neuland.ai HUB
Your requirement
The German Tax Advisory Act (StBerG) sets strict requirements for handling confidential client information. Technical service providers must demonstrably meet these professional rules.
neuland.ai HUB
Your requirement
Patient data is among the most sensitive information there is. Using AI in healthcare requires professional confidentiality and data protection to come together at the highest level.
neuland.ai HUB
Your requirement
The Digital Operational Resilience Act requires financial entities to ensure the resilience of their entire ICT supply chain, including all AI service providers. If your AI provider isn't DORA-ready, neither are you.
neuland.ai HUB
Governance
Where neuland.ai HUB runs, which models it uses and which subprocessors are involved.
AI is being used anyway. What matters is whether it happens in a governed, controlled and auditable way within a secure environment.
Technical and organizational measures
Our TOMs cover every layer at which data must be protected. The measures are documented and available in the Trust Center.
For your review
All contracts, agreements and certificates are available for direct download in the Trust Center.
FAQ
See how companies put AI to productive use: practical examples from real use cases.
With ready-made documents: the DPA under Art. 28 GDPR with the subprocessors, documented TOMs, the ISO 27001 and ISO 9001 certificates, and supplementary agreements, including for DORA and BRAO, all in the Trust Center. The assessment is up to your organization.
Yes, on-premises in your own data center. In EU operation, processing takes place primarily in Germany and the EU; which subprocessors are involved depends on your choice of connectors, and all of them are named in the DPA.
Yes. Roles define who may use which AI, and the log shows every tool call. This supports the documentation your organization keeps under the EU AI Act; you classify your use cases yourself.
neuland.ai HUB works with permissions per role, and access is logged so that results are traceable. Before launch, you define together with the works council and data protection which roles may evaluate which logs.
Yes, the log can be exported and audited. Admins define which roles may view it.
Only roles that admins grant this right; everyone else uses agents without changing them. Before a team uses it, every agent is tested with real content.
No. Your data is never used to train language models and stays within your company context.
Including multi-factor authentication, role-based access control (RBAC), automatic locking of inactive accounts, the principle of least privilege and regular access reviews. Data is end-to-end encrypted, web connections use TLS 1.3, remote access runs over VPN. All measures are documented and available in the Trust Center.
Including the DPA under Art. 28 GDPR, the SaaS terms and conditions, the DORA, BRAO and Microsoft supplementary agreements, the data protection compliance overview and the ISO 27001 and ISO 9001 certificates, each in German and English.
Yes. Models can be swapped without fundamentally changing the platform; depending on your requirements, they are run sovereignly or connected via a cloud API. Rödl runs self-hosted open-source language models directly in neuland.ai HUB, in a private cloud in Germany.
From AI strategy to a running platform: we show you the way. neuland.ai complies with GDPR, DORA and BRAO and is designed for secure use in regulated organizations.