AI security, governance and transparency
The AI proposes. The auditor decides.
For a profession whose product is assurance, how the AI behaves is a security question. dnl is built so the AI is reviewable, contained, and always under the auditor's control.
AI generates
Probabilistic outputs, with source reference and supporting excerpt.
Clearly marked
Visually distinguished, editable, filterable, never auto-entered.
Auditor decides
Reviews, approves and signs the work product.
Your data never trains our AI
By default, customer data is never used to train or fine-tune our models. Any training use requires your explicit, written, opt-in consent, and our AI sub-processors are contractually bound to the same rule.
No free-form prompt surface
No open prompt box for end users; prompts and output formats are controlled by dnl, removing the primary prompt-injection vector by design.
Traceable to its source
Each affirmative answer carries a source reference and a supporting excerpt, so any conclusion can be followed back to the evidence it rests on in the audit trail.
A defined AI-governance model
Technical AI design and AI governance, risk and compliance are owned by distinct accountable functions, with four-eyes on AI outputs.
Carries forward for you, not across clients
Roll-forward carries information year-over-year for the same client only. One client's data never influences another.
Designed for the EU AI Act
Our AI is advisory and must be validated by qualified professionals. GDPR-compliant, ISO 27001-certified, preparing for EU AI Act compliance.
Data protection and privacy
Built for the GDPR from the ground up
Anchored on the EU GDPR and our ISO/IEC 27001 certification, and built to meet UK GDPR and the Australian Privacy Act 1988.
We act as your processor
Under the GDPR you are the controller and dnl the processor. We process only on your documented instructions, governed by an Article 28 DPA in every contract.
A dedicated DPO
An external Data Protection Officer (heyData GmbH, Berlin), reachable at datenschutz@heydata.eu.
No profiling, no automated decisions
We do not profile, make automated decisions, or combine personal data across databases. Personal data is limited to contact and authentication details.
Full data-subject rights
Access, export and erasure at any time. We maintain a Register of Processing Activities under GDPR Article 30.
Breach notification
A documented procedure aligned with GDPR Articles 33–34; notification without undue delay and support for the 72-hour supervisory-authority window.
Data ownership, retention and portability
You decide what happens to your data
You own your data
Customers retain full ownership and can export, review or delete their data at any time.
Export in standard formats
Word, PDF and Excel, packaged with evidence where relevant, and through our REST API.
Clear retention
Retained for the duration of your contract; operational logs up to 30 days and backups up to 90 days.
Questions about how our AI is governed?
Leave your details and someone from our team will get in touch to talk through how the AI is governed, what it can and cannot do, and how your data is handled.
Contact form loads after consent
This form is provided by HubSpot and sets cookies, so it loads only once you accept functional cookies. You can also email hello@dnlab.de.
