Because the security of your data matters to us
An efficient and ethically sound use of AI requires maximum security and legal compliance. Our phone AI, built on our reference platform EIKI®, was designed to be GDPR- and EU AI Act-compliant, with EU hosting and clear tenant separation based on a containerized microservice architecture. In addition, full data sovereignty remains with the customer.
Step Testing Process
Before going live, EIKI® undergoes a 13-step quality, security, and compliance testing process that ensures the phone AI meets data protection requirements and transparency obligations. It is also continuously tested for system stability and manipulation resistance.
For us, data protection isn't just a formal compliance matter — it's a key part of our technological responsibility.
Hosting & Infrastructure: the foundation of our security architecture
EIKI® runs exclusively on Microsoft Azure's European cloud infrastructure; the LLMs are hosted by their respective providers. We use ElevenLabs to configure the phone AI, which is also operated within the EU.
The technical architecture is based on a containerized microservice approach: individual system components run in separate, isolated software containers (Docker) and are centrally orchestrated via Kubernetes. This allows the various functions to be scaled and controlled independently and flexibly. As a result, each customer receives an individually isolated workspace.
Our phone AI's system architecture follows a supervisor-controlled multi-agent model: an overarching control mechanism coordinates specific functional modules for dialogue management, data access, and process logic. This separation enables high transparency, operational reliability, and minimal systemic dependencies.
Our architecture guarantees:
- strict tenant separation
- isolated deployment per customer
- flexible scalability without compromising security
- technical separation of development and production environments
The various system components communicate via clearly defined, secured interfaces. Alternatively, EIKI® can also be operated in the customer's Azure tenant or provided as a fully on-premise integrated solution.
You retain full data sovereignty
We follow the principle of complete data sovereignty: the data collected is used and processed exclusively for its intended purpose, within the scope of the previously agreed use case. Customer data is stored in a separate, managed Postgres database per tenant. Access concepts, role models, and permission criteria are defined on a project-specific basis.
Project-relevant system activities can be logged on request and evaluated and analyzed as part of monitoring. On this basis, we can ensure traceable documentation of system usage and continuous visualization of your performance.
In line with the data minimization principle, only the necessary and required data content is transmitted for specific use cases, such as campaigns. More complex integration processes are possible step by step, ensuring full control and transparency over the respective data flows at all times. In addition, concrete deletion concepts are defined to ensure traceable data cleanup.
Customer data is never used to train our AI.
Controlled integration of Large Language Models (LLMs)
The AI models run at the respective provider (model manufacturer) as an instance in Europe. In principle, any LLM suited to conversation can be connected. In addition, local open-source LLMs are also possible.
Modern language models are connected to existing systems such as SAP, CRM, or ERP solutions through clearly defined, secured API interfaces. The APIs used (REST API/GraphQL) and providers are audited for GDPR compliance. Specific, binding principles apply to ensure high data security.
Zero-Retention Policy
Information transmitted is not stored or processed for training purposes by the model provider.
Isolated Model Logic
The AI model and customer database are strictly separated – no mixing of system and business data.
The integration has no dependency on the release cycles of external applications, ensuring lasting system stability and a high degree of planning security. Dedicated, isolated, or fully self-operated open-source models can also be integrated as needed. Control over all data processing activities always remains with the operator.
GDPR and EU AI Act compliance
Our platform was designed with European regulatory requirements in mind, ensuring a GDPR-compliant integration and rollout of the AI. EIKI® is implemented based on the requirements of the EU AI Act and a project-specific assessment of the particular use cases.
This includes, for example:
- EU hosting
- Clearly defined data processing agreement structures (DPA)
- Purpose limitation and role-based access concepts
- Logging of key system activities
- Definition of guardrails for high control and steering of the AI model
- Transparency obligation in dialogue: the AI identifies itself as such
In addition, as part of our 13-step quality management testing, EIKI® is regularly checked for compliance with data protection requirements and undergoes other quality and security tests, such as detecting manipulation attempts by other AIs or external parties.
Learn moreThis way, we not only ensure that all activities of our phone AI are legally compliant, but also enable transparent AI use and ensure high customer acceptance.
More on governance & process quality
Do you have a question about data protection or our compliance architecture?
Feel free to contact us — we're happy to help at any time.
On request, we can provide additional technical documentation, DPA materials, or detailed security information. Our system activities and processes are transparent and auditable.
We consider security, transparency, and quality management to be core corporate responsibilities.
