A contract management system that meets the most demanding data protection criteria
This page describes how Vakka's security is arranged technically.
Documents are classified by protection level
You decide what the AI is allowed to see.
Normal security level documents
A contract that is analysed and indexed for search. Values extracted by AI are marked as AI-generated until a human has approved them.
Confidential documents
Personal data or other selected information is redacted before analysis. That information never reaches the search index or the AI, and it is not shown to users without a sufficient clearance level.
Archive-only documents
No information reaches search or the AI. Contracts and documents like these can still be stored and archived in Vakka.
Every AI answer is checked before it is shown
EU stack and governance
An EU stack, no exceptions
- All persistent data in the EU — documents, database, search indexes, backups and logs
- Language models run in EU data centres; on the Enterprise tier the analysis is performed by a subprocessor whose data processing agreement also covers special categories of personal data
- Text recognition (OCR) in the EU, with no persistent storage
- Your data is never used to train AI models — not by us and not by our subprocessors.
Governance and traceability
- AI spend caps and a usage log per organisation: vendor, model, tokens, cost.
- Tool scoping for Skills and technical isolation against prompt injection.
- Every AI-produced value is marked — a human confirms before use.
- Full data export at any time.
Agreements and subprocessors
Data processing agreement
A GDPR-grade DPA is published and forms part of every customer agreement. Equivalent data processing agreements are in place with our subprocessors.
Subprocessor list
Our subprocessors are named in the data processing agreement published on this site. We give 30 days' notice before adding or changing one. More: tietoturva@vakka.ai.
Vulnerability reports
Report findings to tietoturva@vakka.ai. We respond within one business day and keep you posted on the fix.
Want to talk in more detail?
Data protection and architecture questions go straight to the technical team at tietoturva@vakka.ai. We respond within one business day.