How Alix is built.
This page describes the architecture, not the aspiration. Where something is not yet in place, it says so.
Where your data lives
Alix is hosted in Europe and your material is processed under European law. Your documents remain your documents: Alix indexes them for retrieval, it does not acquire them.
- European hosting for processing and storage
- No transfer of customer material outside the hosting region
- Data lifecycle under your control, including deletion
Who can see what
The permission model is the part most retrieval tools get wrong. Alix does not build a second, parallel set of access rules that has to be kept in step with yours. It reads the rights that already exist in the source system and answers within them.
- Access rights inherited from the connected source systems
- A user is never shown a passage they could not open directly
- Withheld sources are declared, never silently folded into an answer
- Permission changes at source take effect in Alix
Encryption
Encrypted in transit and at rest. There is no configuration in which this is switched off.
- Encrypted in transit
- Encrypted at rest
- No customer-facing option to disable either
What we do not do
We do not train on customer data. Not to improve the service, not in aggregate, not with material stripped of identifiers. Your documents are used to answer your questions and for nothing else.
- No training on customer data
- No use of customer material to improve models
- No sharing of customer material between tenants
Audit
A full audit trail runs over sources and outputs. What was asked, which sources were consulted, and what was returned, recorded so it can be reviewed rather than reconstructed.
- Query and response history
- Source consultation recorded per answer
- Reviewable by your own governance function
Certification status
Stated plainly, because a badge you have not earned is worse than no badge at all.
GDPR
Operating practice
Alix processes personal data under the General Data Protection Regulation, in Europe. GDPR is a legal obligation and an operating practice, not a certificate, and it is not presented here as one.
ISO/IEC 27001
Upcoming
This certification is upcoming and is not yet held. We will publish the certificate here when it is issued, and not before.
SOC 2 Type II
Upcoming
This certification is upcoming and is not yet held. Type II requires an observation period, so it will remain upcoming for some time after the controls themselves are in place.
Nothing on this page should be read as a certification we hold today unless it is marked as held.
Questions your security team would ask
They are the right questions, and we would rather answer them early than late. Send them with your access request and they will reach someone who can answer properly.