Trust Center
Data and AI sovereignty
Updated on July 22, 2026
Whoever controls the model of your operation controls your operation. At Mappier, that control is entirely yours, and this page explains how we guarantee it.
Documents and policies · public access
Privacy and governance
Data and AI sovereignty
Transparency
Coming soon
In short
- You own your knowledge. What goes into the platform is yours, and stays yours.
- We don't train AI models on your content, and we never sell your data.
- No AI lock-in. We can swap the model underneath without tying your operation to a vendor.
- Every AI call is logged and auditable: who asked, when, which model answered, and what it accessed.
- No AI agent goes live without being evaluated first, against criteria defined in advance — and the result decides whether it switches on.
- An AI agent never sees more than the person in its place would see.
Mappier is designed so that intelligence works in your favor without you losing control over your data. This page lays out, in plain language, our stance on data and AI sovereignty: what is already live, and what is worth asking any platform before trusting it with your operation.
1. You own your knowledge
In the age of AI, the value of an operation lives in the knowledge accumulated about it: how things connect, what has worked, where the risks are. That knowledge is yours, and our premise is simple: it must not migrate, silently, into anyone's AI model.
The content you load into Mappier stays yours. We act as a processor, on your behalf, to make the platform work. We don't sell personal data and we don't hand your content to third parties to use for their own ends.
2. AI sees only what it needs
Collecting and exposing less is a design decision, not a configuration toggle. When an AI agent needs to consult your operation, it receives only what the task requires, and personal data is minimized before it reaches the model.
Not every question needs AI. Whenever a clear, deterministic rule solves it, the platform answers through that rule, without going through the AI. Less surface exposed to the model means less risk, by default.
The same goes for your documents. When you upload a file, reading and extracting its content happens inside our own infrastructure — not in a third-party extraction service. Only after that step, and with personal data already minimized, does an AI model ever see the content.
3. No model lock-in
Mappier doesn't tie your operation to a single AI vendor. The model answering underneath is a replaceable part: we can swap it for one that is more capable, cheaper or better suited to a requirement, without you having to change anything in your day-to-day.
And when AI is unavailable or isn't the right tool, intelligence degrades gracefully: the platform keeps working through deterministic paths instead of simply stopping. Vendor independence is a guarantee of continuity, not just of price.
4. Your knowledge in a layer that is yours
Mappier models your operation as a digital twin: the entities of your business, how they relate, and the processes that connect them. This knowledge layer exists independently of the AI model, and it is this layer, not the model, that carries the value.
The more you use the platform, the richer this model of your business becomes. That gain stays with you: it feeds your own decisions and workflows, not the weights of a third-party model.
5. Permissions that mirror your organization
Who can see and do what is defined by you, at the level of each person, team and action. And the rule applies equally to people and to AI agents: an agent inherits exactly the permissions of whoever invokes it.
In practice, an AI agent never sees more than the person in its place would see. Sensitive capabilities start switched off and are only enabled explicitly and with an audit trail. AI governance is the same governance as your organization, not a separate system.
6. Logged, auditable and reversible
Every AI call leaves a trace. Per call, we log who asked, when, which model answered, what was accessed and what the outcome was. This makes it possible to reconstruct a decision after the fact, account for it in an audit, and demonstrate causality when it matters.
And that trail is a single one. What an automation does and what an AI agent does go into the same execution log, with the origin marked and the previous state preserved — there is no separate “AI log” with looser rules. Whoever audits the operation looks in one single place and sees who acted, what changed and what was undone.
On the action side, what an agent does in your operation is reversible: each change can be kept, discarded or undone. A reversible action is what allows giving AI more autonomy with less risk, because a mistake is always recoverable.
7. Evaluated before it goes live
Trusting an AI agent shouldn't be an act of faith. Before releasing an agent on the platform, we put it through an evaluation battery with criteria defined before the test — the same instructions, the same tools and the same limits it will have in production. If the result doesn't meet the bar, the agent doesn't go live; that is how we chose, with data, the model that answers today.
Part of these checks runs automatically on every code change — including resistance tests against manipulation attempts through hidden instructions (prompt injection) and the guarantee that sensitive capabilities start switched off. Evaluation is not a one-off event: it is a permanent gate between a change and you.
8. The assurance ladder
Not every workload needs the same level of protection. Instead of treating everything alike, we adopt an assurance ladder and run each task on the rung it actually requires.
Our declared rung combines two things: AI processing in the cloud with zero retention, where the provider doesn't store, train on or reuse your content, and a control layer that is yours (the modeling of the business, the permissions and the audit trail described above). For operations with specific residency or regulatory requirements, we discuss the processing region case by case before any commitment. Beneath all this, the infrastructure itself follows the same principle: our systems operate with short-lived federated identity, with no permanent access keys that could leak.
9. Questions to ask any AI vendor
These are the questions we consider fair for any buyer to ask, of Mappier or of any AI platform. Here are our answers.
- Do you train AI models on our data?
- No. Your content is not used to train models, ours or third parties'.
- Are we locked into a single AI vendor?
- No. The model is replaceable, and the platform keeps operating through deterministic paths when AI isn't the right tool.
- Can we audit what the AI did?
- Yes. Every AI call is logged with actor, time, model, what was accessed and the outcome.
- What if an AI agent does something wrong?
- Actions are reversible and the agent only acts within the permissions of whoever invoked it. A mistake is recoverable.
- Can an agent see data the person couldn't?
- No. Agents inherit the user's permissions, and personal data is minimized before reaching the model.
- How do you know the AI works before releasing it?
- No agent goes live without passing an evaluation battery with criteria defined before the test, on the same path it will use in production. The result decides whether the agent switches on — and which model answers.
- Who processes our documents?
- We do. Reading and extracting content from your files happens in our own infrastructure, without going through third-party extraction services. Personal data is minimized before any contact with an AI model.
- Where is the data processed?
- In the cloud with zero retention. For specific residency requirements, we discuss the processing region case by case.
10. Talk to us
Evaluating Mappier and need to go deeper on any of these points with your security, legal or procurement team? Reach out through the contact form or directly to our Data Protection Officer: start@mappier.app. For how we handle personal data in detail, see our Privacy Policy.