INTEGRATED CONTROLS

Security throughout the platform.

Access, data sources, models, and events can be controlled based on business requirements and the sensitivity of the information.

COMPLIANCE

Designed for demanding requirements

GxP / GAMP 5

First in the Nordics

The only certified provider in the Nordics. Ready for FDA and EMA inspection from day one.

NIS2

Security, traceability, and risk management are integrated into the architecture. Not added as an afterthought.

DORA

Documented governance, risk management, and complete logging of every AI call.

SOC 2

Security controls designed based on SOC 2 principles.

ISO 27001

Systematic information security work based on the requirements of ISO 27001.

GDPR & EU AI Act

Personal data processing and AI governance are designed to meet the applicable requirements of the GDPR and the EU AI Act.

Comprehensive support for GxP/GAMP 5, NIS2, DORA, SOC 2, and ISO 27001 in a Swedish platform tailored for organizations with high demands.

Comprehensive support for GxP/GAMP 5, NIS2, DORA, SOC 2, and ISO 27001 in a Swedish platform tailored for organizations with high demands.

DATA FLOW

From data source to answer, within the right boundaries

Violet connects to the business's data sources with defined permissions. Access, processing, and storage are adapted according to the information's classification and the organization's requirements.

Data source

Documents, systems, and databases are connected through controlled integrations.

Data source

Documents, systems, and databases are connected through controlled integrations.

Authorization check

The user only gains access to the information allowed by their role.

Authorization check

The user only gains access to the information allowed by their role.

Model and treatment

Model, operating environment, and workflow are selected based on the sensitivity of the data and the area of use.

Model and treatment

Model, operating environment, and workflow are selected based on the sensitivity of the data and the area of use.

Answers and traceability

Relevant events are logged so that usage can be monitored.

Answers and traceability

Relevant events are logged so that usage can be monitored.

Access control

Control access based on users, roles, and the organization's permission structure.

Identity and login

Connect your organization's identity provider for centralized management of users and access.

Encryption

Protect information during transmission and storage using established encryption methods.

Logging and auditing

Follow relevant events and usage through logs and audit trails.

Delimited data sources

Determine which data sources each solution, assistant, or user group is allowed to use.

Controlled model access

Control which models are allowed to process different types of information and under what conditions.

OPERATIONS AND DATA HOSTING

Operations according to business requirements

The operating environment and choice of model are adapted according to the classification of the information, existing infrastructure, and the organization's risk assessment.

Swedish cloud environment

Processing and storage in Swedish infrastructure with defined geographical boundaries.

Isolated environment

Separate environment for operations requiring a higher degree of isolation and control.

Local installation

Local installation

Models and data can be kept within the organization's own infrastructure when requirements justify it.

FAQ

Frequently asked questions.

Where is our data stored and processed?

Processing and storage take place in Swedish infrastructure. Which operating environment is used is determined together with you based on the classification of the information: Swedish cloud environment, isolated environment, or installation in your own infrastructure. Your data is not used to train public AI models. If you also choose to use general models for tasks without sensitive information, it is clearly stated which information may be handled there.

What does the CLOUD Act mean for us?

The CLOUD Act allows US authorities to request data from US providers, even when the data is stored in Europe. Violet is a Swedish company and your solution is hosted in Swedish infrastructure. Which subcontractors are included in your specific solution is reported before deployment, so that you can factor this into your own risk assessment.

Can we run the models locally?

Yes. Models can be run within your own infrastructure, which means that both data and inference remain there. Which models are suitable depends on the task and what hardware you have access to. We will go through the options in the analysis phase.

How does Violet support our work with NIS2 and DORA?

NIS2 and DORA place demands on your organization. The platform delivers the parts you need to be able to present in that work: documented access control, logging of events, clarity regarding the supply chain, and supporting data for your risk management. The responsibility for compliance remains with you, and we assist with the documentation.

What applies to us according to the EU's AI Act?

Which requirements apply depends on how you use AI, not on the platform itself. The transparency requirements in Article 50 have been applied since August 2, 2026. The requirements for high-risk systems under Annex III are managed through the amending regulation from July 2026 until December 2, 2027, and until August 2, 2028 for AI that is a safety component in a product. We help you map out where your use cases fall and what documentation you need.

What is Violet's role according to GDPR?

Violet is the data processor for the processing that takes place in the platform. You are the data controller and decide which information may be used. A data processing agreement, a list of sub-processors, and a description of the processing are developed as part of the agreement.

What is logged, and how long is the information stored?

Calls and relevant events are logged so that usage can be followed up afterwards. The logs can be exported for internal follow-up or external review. How long data and logs are saved is configured according to your requirements for deletion.

Ready to build your
AI capability?

Secure by default. Flexible by design.

Ready to build your
AI capability?

Secure by default. Flexible by design.

Ready to build your
AI capability?

Secure by default. Flexible by design.