// TRUST
Trust and security
Last updated 23 August 2026
Data residency and hosting
Infrastructure for customer workloads is EU-resident. The specific region and provider are confirmed per engagement and recorded in the applicable data processing agreement.
Air-gapped on-premise deployments keep data inside the customer’s environment. In that mode PowerIntel does not host customer data and makes no external network calls from the runtime.
Customer data and model training
Customer data is not used to train models. Not foundation models, not fine-tunes, not evaluation corpora we reuse across customers.
Providens generates drafts from the customer’s own sources and a methodology corpus configured for that engagement. Outputs are reviewed by the customer’s operators before anything is finalized. The platform proposes; humans dispose.
Where a deployment uses a third-party model API, we contract for inference-only processing and prohibit the provider from using customer content to train or improve models.
Subprocessors
Subprocessors depend on the deployment mode. Shared-cloud and dedicated-cloud engagements use EU-hosted infrastructure and, where selected, a model-inference provider. Air-gapped deployments do not send customer data to PowerIntel or to a model API.
The rows below describe the processors typically involved in EU cloud deployments, plus the processor used for the website contact form. A current list for a given engagement is available on request.
Amazon Web Services (AWS)
Cloud infrastructure and hosting — EU region, confirmed per engagement
Anthropic
Model inference on shared-cloud deployments that use the Claude API — region per engagement
AWS Bedrock
Model inference on deployments configured for Bedrock in the EU — region confirmed per engagement
Resend
Website contact form email delivery — name, organization, email, and message content. Outbound form email is dispatched from Resend's EU (Ireland) region; Resend account data, email metadata, logs, and API records remain US-resident.
Deployment modes
Providens is the same platform in every engagement. Methodology, data sources, AI runtime, and deployment mode are calibrated per customer. Three modes are available:
Shared EU cloud — for non-classified environments. EU-resident infrastructure; region and provider confirmed per engagement.
Dedicated EU cloud — for stricter isolation and compliance requirements. Still EU-resident; the runtime is not shared with other customers.
Air-gapped on-premise — for environments where no external network calls are allowed. Self-hosted models (Llama / Mistral or equivalent) run inside the customer’s perimeter.
Access control and authentication
Access to customer deployments is restricted to named operators designated by the customer and to a small PowerIntel support set, only when the contract and deployment mode allow it. Air-gapped deployments are operated entirely by the customer.
Authentication is configured per engagement (typically SSO or equivalent enterprise identity). Authorization is role-based: who can ingest sources, who can review drafts, who can finalize. Providens does not publish, send, or act on its own. Nothing leaves the review loop without an explicit operator action.
Retention and deletion
Retention follows the customer contract. We do not keep customer operational data longer than the engagement requires.
On written request, or at the end of the engagement, we delete customer data from systems we operate, including backups, within the period set in the contract. Air-gapped deployments retain and delete data under the customer’s own policies; PowerIntel has no residual copy.
Website data is covered separately on the Privacy page.
Incident response posture
We maintain an incident-response process for confidentiality, integrity, and availability events affecting systems we operate.
Personal-data breaches are assessed against GDPR. Where a breach is notifiable, we inform the affected customer without undue delay so the customer can meet its own Article 33/34 obligations. We aim to notify within 72 hours of becoming aware of a notifiable breach, unless a contract sets a shorter clock.
We do not claim a certified information-security management system. Controls described on this page are operational practice, not a substitute for a completed audit.
Data processing agreements
Where PowerIntel processes personal data on a customer’s behalf, we enter into a data processing agreement that meets GDPR Article 28. The DPA covers instructions, confidentiality, subprocessors, security measures, deletion, and audit cooperation appropriate to the deployment mode.
To request a DPA, or a current subprocessor list for an engagement, contact us at the address on the Legal notice.