Features Pricing FAQ Contact Try Free

Security is not a feature. It is the architecture.

Every design decision at CookieAI starts with one question: does this protect client data? From encryption primitives to deployment topology, security is the foundation, not an afterthought.

FADP compliant
GDPR compliant
No third-party AI APIs

You choose where your data lives

Two deployment models, one commitment: your data remains under your control at all times.

On-Premise

  • Data never leaves your office network
  • No internet connection required for AI inference
  • You control the hardware, the software, and the keys
  • Full air-gap capability

Cloud

  • Data stored on European servers
  • Encrypted in transit and at rest
  • No data shared between customers
  • Full data deletion on account removal

Defense in depth, layer by layer

Encryption

AES-256-GCM at rest. TLS 1.3 in transit. HTTPS everywhere, no exceptions. Your data is unreadable to anyone without the keys.

Authentication

Two-factor authentication (TOTP). Session management with 256-bit entropy tokens. Maximum 10 concurrent sessions per user.

Access Control

Role-based permissions with strict team isolation. Leaders maintain oversight of member conversations. No cross-team data leakage.

Intrusion Detection

Fail2ban protection against SSH brute force and bot scanning. Rate limiting on all API endpoints. Automated threat response.

Audit Trail

FADP-compliant access logging. Full data export capability on request. Right to erasure honored within 48 hours.

Infrastructure

Nginx with strict security headers: HSTS, Content Security Policy, X-Frame-Options. No unsafe-eval. Server tokens hidden from all responses.

Built for regulated industries

CookieAI meets the requirements of Swiss and European data protection law by design, not by bolt-on compliance.

FADP

Full compliance with the Swiss Federal Act on Data Protection. Right to erasure, data export on request, and comprehensive access logging are built into every deployment.

GDPR

Compliant with the EU General Data Protection Regulation. Data minimization by default, explicit consent management, and the right to be forgotten are core platform capabilities.

Open Source Models

No data is sent to third-party AI services like OpenAI or Anthropic. On-premise deployments process everything locally. CookieAI runs Qwen3 30B, a fully auditable open-source model. You can inspect every layer of the stack.

What we do NOT do

Clear boundaries matter more than vague promises. Here is what we will never do with your data.

We do NOT train AI models on your data
We do NOT share data between customers
We do NOT store data after account deletion
We do NOT require internet for on-premise AI inference
We do NOT use third-party AI APIs

Ready to see it in action?