Products
Sherpa
Drafter
Researcher
Reviewer
Audiences
MedTech
Startups
Consultants
Guideways.ai
About us
Technology
FAQ
Trust
News & Insights
Contact us
Built on defense-in-depth infrastructure in the European Union. Validated every day. No customer data stored by AI sub-processors.
MFA enforced for every account. Optional SSO via Google or Microsoft.
Data separation enforced at the infrastructure layer, not just application code.
TLS 1.2+ in transit, AES-256 at rest. No unencrypted data touches disk or leaves our network.
Threat detection, immutable audit logs, and vulnerability scanning, 24/7.
All data stored and processed in the EU. AI services run in EU regions and store nothing.
GDPR Article 28 DPA, documented sub-processors, and no AI training on customer data.
A high-level view of how requests and data flow through independent layers of protection.
Web app firewall
Encrypted gateway
Identity service
Application
Public reference data
Your private data
AI services
Complete self-assessment against the Cloud Controls Matrix. Fully encompasses ISO 27001, extends to SOC 2 and NIST.
Automated benchmark validation runs every day. Built on AWS infrastructure certified to SOC 2 and ISO 27001.
Latest CVE detection templates. Continuous container and dependency scanning.
Documentation, legal terms and how to reach our security team.
The third-party services we rely on to deliver Guideways, and what they process.
Our terms of service, including the GDPR Article 28 Data Processing Agreement.
Security questions, vendor assessments, or to report a vulnerability. We welcome responsible disclosure.
Email: security@guideways.ai →