Home / Trust center
Every program is built to pass a procurement review on day one.
This page sets out how we handle data, where it comes from, who controls it, how our AI agents are governed and what a security review will find. Content here is general information, not legal advice.
An EU companySaravus OÜ, Tallinn, under the GDPR
Data in FrankfurtOur database runs in the EU
Every agent run loggedInputs, output, model and approver
DPA on day oneWith the sub-processor list attached
Every program states where its contacts come from and who controls the data.
We are processorOpted-in subscriber audiencesSubscribers who have already opted in to hear from the program's brand. The route we use in opt-in markets such as Germany, Japan and Korea.
We are processorSupplied target listsNamed contacts from your CRM or ABM platform, cleaned and matched before use.
We are controllerLicensed opt-in dataThird-party audiences that pass our due diligence on consent, recency and provenance.
We are controllerContacts we sourceBusiness contacts researched by our agents, used only where the recipient's country allows business email without prior opt-in.
Each country rulebook is reviewed by counsel before we deliver into that country. Any country without one is treated as opt-in.
Our AI agents work under rules a compliance team can audit.
Agents research, write, check and pace. People approve every price, launch, batch release and invoice, and the program owner approves final copy.
| Control | How it works | What you can see |
|---|---|---|
| Human checkpoints | Nine checkpoints per program, each signed by a named person | Who signed, and when |
| Agent limits | Agents may pause a program or honor an opt-out, nothing else on their own | The limit for each agent |
| Run logging | Inputs, output, model, prompt version and cost stored for every run | Run history per program on request |
| Disclosure | Any agent that writes to a person in a conversation says it is AI, in line with Article 50 of the EU AI Act | The disclosure wording |
| Numbers | Every figure in a report comes from our database, never from an agent's guess | The source of each metric |
| Prompt changes | New prompt versions pass an evaluation set before they go live | Version history |
What a security questionnaire will find.
We answer your questionnaire in full and show where each control stands today. SOC 2 and ISO 27001 are on our roadmap.
- Separation by programRow-level security on every table, tested on every release
- EncryptionIn transit and at rest, with secrets held in a vault
- Least accessStaff, reviewers and suppliers see only what their role needs
- Return and deletionProgram data returned or deleted at close, confirmed in writing
The procurement pack, ready before anyone asks.
Data processing agreementArticle 28 terms, with standard contractual clauses where data leaves the EU
Sub-processor listEvery provider, its role and its location
Sample audit trailThe record that travels with every lead
Country rules summaryThe consent route for each market we deliver into