Data and AI sovereignty

Documents and policies · public access

Privacy and governance

Coming soon

Data Processing Agreement (DPA)Coming soon Information Security PolicyComing soon Security certificationsComing soon

1. You own your knowledge

In the age of AI, the value of an operation lives in the knowledge accumulated about it: how things connect, what has worked, where the risks are. That knowledge is yours, and our premise is simple: it must not migrate, silently, into anyone's AI model.

The content you load into Mappier stays yours. We act as a processor, on your behalf, to make the platform work. We don't sell personal data and we don't hand your content to third parties to use for their own ends.

2. AI sees only what it needs

Collecting and exposing less is a design decision, not a configuration toggle. When an AI agent needs to consult your operation, it receives only what the task requires, and personal data is minimized before it reaches the model.

Not every question needs AI. Whenever a clear, deterministic rule solves it, the platform answers through that rule, without going through the AI. Less surface exposed to the model means less risk, by default.

The same goes for your documents. When you upload a file, reading and extracting its content happens inside our own infrastructure — not in a third-party extraction service. Only after that step, and with personal data already minimized, does an AI model ever see the content.

3. No model lock-in

Mappier doesn't tie your operation to a single AI vendor. The model answering underneath is a replaceable part: we can swap it for one that is more capable, cheaper or better suited to a requirement, without you having to change anything in your day-to-day.

And when AI is unavailable or isn't the right tool, intelligence degrades gracefully: the platform keeps working through deterministic paths instead of simply stopping. Vendor independence is a guarantee of continuity, not just of price.

4. Your knowledge in a layer that is yours

Mappier models your operation as a digital twin: the entities of your business, how they relate, and the processes that connect them. This knowledge layer exists independently of the AI model, and it is this layer, not the model, that carries the value.

The more you use the platform, the richer this model of your business becomes. That gain stays with you: it feeds your own decisions and workflows, not the weights of a third-party model.

5. Permissions that mirror your organization

Who can see and do what is defined by you, at the level of each person, team and action. And the rule applies equally to people and to AI agents: an agent inherits exactly the permissions of whoever invokes it.

In practice, an AI agent never sees more than the person in its place would see. Sensitive capabilities start switched off and are only enabled explicitly and with an audit trail. AI governance is the same governance as your organization, not a separate system.

6. Logged, auditable and reversible

Every AI call leaves a trace. Per call, we log who asked, when, which model answered, what was accessed and what the outcome was. This makes it possible to reconstruct a decision after the fact, account for it in an audit, and demonstrate causality when it matters.

And that trail is a single one. What an automation does and what an AI agent does go into the same execution log, with the origin marked and the previous state preserved — there is no separate “AI log” with looser rules. Whoever audits the operation looks in one single place and sees who acted, what changed and what was undone.

On the action side, what an agent does in your operation is reversible: each change can be kept, discarded or undone. A reversible action is what allows giving AI more autonomy with less risk, because a mistake is always recoverable.

7. Evaluated before it goes live

Trusting an AI agent shouldn't be an act of faith. Before releasing an agent on the platform, we put it through an evaluation battery with criteria defined before the test — the same instructions, the same tools and the same limits it will have in production. If the result doesn't meet the bar, the agent doesn't go live; that is how we chose, with data, the model that answers today.

Part of these checks runs automatically on every code change — including resistance tests against manipulation attempts through hidden instructions (prompt injection) and the guarantee that sensitive capabilities start switched off. Evaluation is not a one-off event: it is a permanent gate between a change and you.

8. The assurance ladder

Not every workload needs the same level of protection. Instead of treating everything alike, we adopt an assurance ladder and run each task on the rung it actually requires.

Our declared rung combines two things: AI processing in the cloud with zero retention, where the provider doesn't store, train on or reuse your content, and a control layer that is yours (the modeling of the business, the permissions and the audit trail described above). For operations with specific residency or regulatory requirements, we discuss the processing region case by case before any commitment. Beneath all this, the infrastructure itself follows the same principle: our systems operate with short-lived federated identity, with no permanent access keys that could leak.

9. Questions to ask any AI vendor

These are the questions we consider fair for any buyer to ask, of Mappier or of any AI platform. Here are our answers.

10. Talk to us

Evaluating Mappier and need to go deeper on any of these points with your security, legal or procurement team? Reach out through the contact form or directly to our Data Protection Officer: start@mappier.app. For how we handle personal data in detail, see our Privacy Policy.