How Alix is built.

This page describes the architecture, not the aspiration. Where something is not yet in place, it says so.

Where your data lives

Alix is hosted in Europe and your material is processed under European law. Your documents remain your documents: Alix indexes them for retrieval, it does not acquire them.

  • European hosting for processing and storage
  • No transfer of customer material outside the hosting region
  • Data lifecycle under your control, including deletion

Who can see what

The permission model is the part most retrieval tools get wrong. Alix does not build a second, parallel set of access rules that has to be kept in step with yours. It reads the rights that already exist in the source system and answers within them.

  • Access rights inherited from the connected source systems
  • A user is never shown a passage they could not open directly
  • Withheld sources are declared, never silently folded into an answer
  • Permission changes at source take effect in Alix

Encryption

Encrypted in transit and at rest. There is no configuration in which this is switched off.

  • Encrypted in transit
  • Encrypted at rest
  • No customer-facing option to disable either

What we do not do

We do not train on customer data. Not to improve the service, not in aggregate, not with material stripped of identifiers. Your documents are used to answer your questions and for nothing else.

  • No training on customer data
  • No use of customer material to improve models
  • No sharing of customer material between tenants

Audit

A full audit trail runs over sources and outputs. What was asked, which sources were consulted, and what was returned, recorded so it can be reviewed rather than reconstructed.

  • Query and response history
  • Source consultation recorded per answer
  • Reviewable by your own governance function

Certification status

Stated plainly, because a badge you have not earned is worse than no badge at all.

GDPR

Operating practice

Alix processes personal data under the General Data Protection Regulation, in Europe. GDPR is a legal obligation and an operating practice, not a certificate, and it is not presented here as one.

ISO/IEC 27001

Upcoming

This certification is upcoming and is not yet held. We will publish the certificate here when it is issued, and not before.

SOC 2 Type II

Upcoming

This certification is upcoming and is not yet held. Type II requires an observation period, so it will remain upcoming for some time after the controls themselves are in place.

Nothing on this page should be read as a certification we hold today unless it is marked as held.

Questions your security team would ask

They are the right questions, and we would rather answer them early than late. Send them with your access request and they will reach someone who can answer properly.