Skip to content

Security & data protection

Your data stays where it belongs.

Thero runs in German data centres, every customer gets their own instance, and AI processing never takes your data outside European jurisdiction. This page explains how that works.

The path your data takes

Three stations, all inside European jurisdiction.

EU jurisdiction

Your sources

Connectors read content and access rights. They write nothing back.

Google DriveSharePointGmailConfluenceJira+14 more

Your Thero instance

An environment of your own, in German data centres. The index stores content together with permissions.

  • Frankfurt & Hamburg
  • AES-256 at rest, TLS 1.3 in transit
  • No shared databases

AI processing

Language models run with specialised partners in Germany and Finland.

  • Zero retention, contractual
  • No training on your data
  • Stricter models selectable per use case
HamburgData centre
KölnHeadquarters
FrankfurtData centre
HelsinkiAI partner

Where your data sits

  • Frankfurt and Hamburg: This is where the instances run. Every customer gets their own, with AES-256 at rest and TLS 1.3 in transit.
  • Germany and Finland: This is where the language models compute, under contractual zero retention. No byte travels further.
  • Cologne: This is where your contracting party sits, Syntriq GmbH (Cologne local court, HRB 126391).

Permissions reach all the way into the answer

The filter applies during retrieval itself, not on the finished result.

Q3-Zahlen.xlsx

Lives in SharePoint. Shared with management only.

Shared with: management

Anna, management

“Q3 revenue came to €4.2m.” With a citation pointing at the file.

Jonas, working student

“I have no source on that.” For his search, the document does not exist.

On sync, Thero reads the source's access rules, such as Drive sharing and SharePoint group roles, and mirrors them into the index. Revoke someone's access and the content leaves their answers with the next delta sync.

Control

Anything irreversible waits for a person

Before the AI sends an email or does anything else irreversible, it shows exactly what would happen and waits for approval. With no response, the request counts as declined after five minutes. Your organisation decides which tools run freely, ask first or are blocked.

Evidence

Every run on the record

The audit log records timestamp, process, action, status, duration and the acting person. For audits it filters and exports as CSV.

The facts in brief

Dedicated instance

Every customer gets their own isolated environment for services and databases. There are no shared schemas.

Hosted in Germany

Infrastructure and data storage run in German data centres in Frankfurt and Hamburg.

Encryption

TLS 1.3 in transit, AES-256 at rest. That includes the index's vector databases.

Access & sign-in

Role-based access (RBAC), single sign-on via SAML and OIDC with Entra ID, Google Workspace or Okta, plus MFA.

AI processing in the EU

Language models run with partners in Germany and Finland. Zero retention is contractual: no training on your data.

Contract under German law

DPA under Art. 28 GDPR, signable digitally. Scope and technical measures live in the contract, not just on this page.

Why there is no badge wall here

We will only put an ISO 27001 or SOC 2 badge on this page once the audit report exists. Security questionnaires and vendor assessments we answer today. Write to info@syntriq.de.

Questions from your IT or privacy team?

We answer them directly, happily engineer to engineer.

Last updated: August 2026 · Syntriq GmbH · Frankfurter Str. 148 · 51147 Köln

Security and privacy – TheroAI