Security & data protection
Your data stays where it belongs.
Thero runs in German data centres, every customer gets their own instance, and AI processing never takes your data outside European jurisdiction. This page explains how that works.
The path your data takes
Three stations, all inside European jurisdiction.
Your sources
Connectors read content and access rights. They write nothing back.
Your Thero instance
An environment of your own, in German data centres. The index stores content together with permissions.
- Frankfurt & Hamburg
- AES-256 at rest, TLS 1.3 in transit
- No shared databases
AI processing
Language models run with specialised partners in Germany and Finland.
- Zero retention, contractual
- No training on your data
- Stricter models selectable per use case
Where your data sits
- Frankfurt and Hamburg: This is where the instances run. Every customer gets their own, with AES-256 at rest and TLS 1.3 in transit.
- Germany and Finland: This is where the language models compute, under contractual zero retention. No byte travels further.
- Cologne: This is where your contracting party sits, Syntriq GmbH (Cologne local court, HRB 126391).
Permissions reach all the way into the answer
The filter applies during retrieval itself, not on the finished result.
Q3-Zahlen.xlsx
Lives in SharePoint. Shared with management only.
Shared with: managementAnna, management
“Q3 revenue came to €4.2m.” With a citation pointing at the file.
Jonas, working student
“I have no source on that.” For his search, the document does not exist.
On sync, Thero reads the source's access rules, such as Drive sharing and SharePoint group roles, and mirrors them into the index. Revoke someone's access and the content leaves their answers with the next delta sync.
Control
Anything irreversible waits for a person
Before the AI sends an email or does anything else irreversible, it shows exactly what would happen and waits for approval. With no response, the request counts as declined after five minutes. Your organisation decides which tools run freely, ask first or are blocked.
Evidence
Every run on the record
The audit log records timestamp, process, action, status, duration and the acting person. For audits it filters and exports as CSV.
The facts in brief
Dedicated instance
Every customer gets their own isolated environment for services and databases. There are no shared schemas.
Hosted in Germany
Infrastructure and data storage run in German data centres in Frankfurt and Hamburg.
Encryption
TLS 1.3 in transit, AES-256 at rest. That includes the index's vector databases.
Access & sign-in
Role-based access (RBAC), single sign-on via SAML and OIDC with Entra ID, Google Workspace or Okta, plus MFA.
AI processing in the EU
Language models run with partners in Germany and Finland. Zero retention is contractual: no training on your data.
Contract under German law
DPA under Art. 28 GDPR, signable digitally. Scope and technical measures live in the contract, not just on this page.
Why there is no badge wall here
We will only put an ISO 27001 or SOC 2 badge on this page once the audit report exists. Security questionnaires and vendor assessments we answer today. Write to info@syntriq.de.
Questions from your IT or privacy team?
We answer them directly, happily engineer to engineer.
Last updated: August 2026 · Syntriq GmbH · Frankfurter Str. 148 · 51147 Köln