INTEGRATED CONTROLS
Security throughout the platform.
Access, data sources, models, and events can be controlled based on business requirements and the sensitivity of the information.
COMPLIANCE
Designed for demanding requirements
GxP / GAMP 5
First in the Nordics
The only certified provider in the Nordics. Ready for FDA and EMA inspection from day one.
NIS2
Security, traceability, and risk management are integrated into the architecture. Not added as an afterthought.
DORA
Documented governance, risk management, and complete logging of every AI call.
SOC 2
Security controls designed based on SOC 2 principles.
ISO 27001
Systematic information security work based on the requirements of ISO 27001.
GDPR & EU AI Act
Personal data processing and AI governance are designed to meet the applicable requirements of the GDPR and the EU AI Act.
DATA FLOW
From data source to answer, within the right boundaries
Violet connects to the business's data sources with defined permissions. Access, processing, and storage are adapted according to the information's classification and the organization's requirements.
Access control
Control access based on users, roles, and the organization's permission structure.
Identity and login
Connect your organization's identity provider for centralized management of users and access.
Encryption
Protect information during transmission and storage using established encryption methods.
Logging and auditing
Follow relevant events and usage through logs and audit trails.
Delimited data sources
Determine which data sources each solution, assistant, or user group is allowed to use.
Controlled model access
Control which models are allowed to process different types of information and under what conditions.
OPERATIONS AND DATA HOSTING
Operations according to business requirements
The operating environment and choice of model are adapted according to the classification of the information, existing infrastructure, and the organization's risk assessment.
Isolated environment
Separate environment for operations requiring a higher degree of isolation and control.
Models and data can be kept within the organization's own infrastructure when requirements justify it.
FAQ
Frequently asked questions.
Where is our data stored and processed?
Processing and storage take place in Swedish infrastructure. Which operating environment is used is determined together with you based on the classification of the information: Swedish cloud environment, isolated environment, or installation in your own infrastructure. Your data is not used to train public AI models. If you also choose to use general models for tasks without sensitive information, it is clearly stated which information may be handled there.
What does the CLOUD Act mean for us?
The CLOUD Act allows US authorities to request data from US providers, even when the data is stored in Europe. Violet is a Swedish company and your solution is hosted in Swedish infrastructure. Which subcontractors are included in your specific solution is reported before deployment, so that you can factor this into your own risk assessment.
Can we run the models locally?
Yes. Models can be run within your own infrastructure, which means that both data and inference remain there. Which models are suitable depends on the task and what hardware you have access to. We will go through the options in the analysis phase.
How does Violet support our work with NIS2 and DORA?
NIS2 and DORA place demands on your organization. The platform delivers the parts you need to be able to present in that work: documented access control, logging of events, clarity regarding the supply chain, and supporting data for your risk management. The responsibility for compliance remains with you, and we assist with the documentation.
What applies to us according to the EU's AI Act?
Which requirements apply depends on how you use AI, not on the platform itself. The transparency requirements in Article 50 have been applied since August 2, 2026. The requirements for high-risk systems under Annex III are managed through the amending regulation from July 2026 until December 2, 2027, and until August 2, 2028 for AI that is a safety component in a product. We help you map out where your use cases fall and what documentation you need.
What is Violet's role according to GDPR?
Violet is the data processor for the processing that takes place in the platform. You are the data controller and decide which information may be used. A data processing agreement, a list of sub-processors, and a description of the processing are developed as part of the agreement.
What is logged, and how long is the information stored?
Calls and relevant events are logged so that usage can be followed up afterwards. The logs can be exported for internal follow-up or external review. How long data and logs are saved is configured according to your requirements for deletion.