Security & Data Protection
Your data stays on your servers.
No cloud calls, no telemetry, no updates that leak data. Our clients' data never leaves their premises.
Architecture
Analysis, development and testing happen exclusively in the client's own environment. No copies of test or production data are made on Realico devices or systems, not even temporarily. We document the architecture technically for our clients' security reviews.
Access
Realico works inside the client's environment, under the client's control and logged. A data processing agreement (DPA) under Article 28 of the General Data Protection Regulation (GDPR) is concluded before the project starts.
Security measures
You keep control of every access: we work with user accounts you issue, behind your multi-factor authentication (MFA) and inside your logging. The access concept and incident handling are agreed before the project starts. Security documentation for your supplier assessment comes with our offer.
NIS2 supply chain
Documentation for security questionnaires is available on request. On-premise deployment lowers supply-chain risk compared with cloud solutions.
Special categories of data
Controlling analyses need commercial data, not individual personal records. We process only what the analysis requires. Where special categories under Article 9 GDPR sit in source systems, they stay there and are not carried into analyses.
Operation & requirements
The solution runs on a server or virtual machine in your data centre. Your team installs updates after approval; there are no automatic online updates. Where language is processed, language models run locally on your hardware; everything else is rule-based. Hardware requirements are set out in writing in Step 1.
Traceability
An audit trail, approvals, and documentation of every rule are part of every project.
Your data stays on your servers; we work under your control.