StaryonSTARYONAI, YOUR LEVERAGE
Security & compliance

Security by design, in both cases.

Whether the AI runs at your site or on our infrastructure, the principle is the same: your documents only ever serve to answer you.

On-premise

Offline by default

No outbound connection required: the server can run without any internet access at all.

Hardware perimeter under control

Processing happens on a machine you own, in a room you control.

Auditable on site

You can have the installation audited on your premises, at any time and without notice.

In the cloud

Hosted in the European Union

The infrastructure sits in the European Union, with no transfer of your documents outside that area.

No training on your data

Your documents and your questions never train or improve a model, neither for us nor for a third party.

Governed subprocessing

A data processing agreement (DPA) documents the processing, the roles and the retention period.

In both cases

Encryption at rest

Your documents and the indexes that make them searchable are encrypted on the storage.

Fine-grained permissions

Access rights are set per team and per folder: everyone sees only what concerns them.

No usage telemetry

No collection of how you use the tool, no statistics sent to third parties, ever.

Traceable answers

Every answer cites the document and the page it comes from, which makes checking possible.

The principle: your documents only serve you

Your documents are indexed to answer your questions, and nothing else. They are never used to train a model, never resold, never analysed for other purposes. This principle does not change with the deployment mode: what varies is where the processing happens and the guarantees that surround it.

Data at rest and access

Your documents and the indexes that make them searchable are encrypted. Access is limited to your teams, with permissions per team and per folder. On-premise, everything lives on your server; in the cloud, on European infrastructure dedicated to your company.

GDPR compliance

On-premise, there is neither a transfer outside the European Union nor a third party keeping your queries: the perimeter is that of your own premises. In the cloud, hosting stays within the European Union, subprocessing is documented and an agreement (DPA) governs the processing. In both cases, we remain available to document the processing for your DPO. See also our comparison and our privacy policy.

See security at work, on your data.

A 30-minute demo, on your data. No commitment.