vakka.aivakka.ai
Security and compliance

A contract management system that meets the most demanding data protection criteria

This page describes how Vakka's security is arranged technically.

Document classes

Documents are classified by protection level

You decide what the AI is allowed to see.

Normal security level documents

A contract that is analysed and indexed for search. Values extracted by AI are marked as AI-generated until a human has approved them.

Confidential documents

Personal data or other selected information is redacted before analysis. That information never reaches the search index or the AI, and it is not shown to users without a sufficient clearance level.

Archive-only documents

No information reaches search or the AI. Contracts and documents like these can still be stored and archived in Vakka.

DLP

Every AI answer is checked before it is shown

Infrastructure

EU stack and governance

An EU stack, no exceptions

  • All persistent data in the EU — documents, database, search indexes, backups and logs
  • Language models run in EU data centres; on the Enterprise tier the analysis is performed by a subprocessor whose data processing agreement also covers special categories of personal data
  • Text recognition (OCR) in the EU, with no persistent storage
  • Your data is never used to train AI models — not by us and not by our subprocessors.

Governance and traceability

  • AI spend caps and a usage log per organisation: vendor, model, tokens, cost.
  • Tool scoping for Skills and technical isolation against prompt injection.
  • Every AI-produced value is marked — a human confirms before use.
  • Full data export at any time.
Data processing

Agreements and subprocessors

Data processing agreement

A GDPR-grade DPA is published and forms part of every customer agreement. Equivalent data processing agreements are in place with our subprocessors.

Subprocessor list

Our subprocessors are named in the data processing agreement published on this site. We give 30 days' notice before adding or changing one. More: tietoturva@vakka.ai.

Vulnerability reports

Report findings to tietoturva@vakka.ai. We respond within one business day and keep you posted on the fix.

Want to talk in more detail?

Data protection and architecture questions go straight to the technical team at tietoturva@vakka.ai. We respond within one business day.