Security

How we protect your data: secure, private, and fully under your control

CID is built for companies that want to use AI without compromising on privacy and control. Security is not an afterthought — it is anchored in the architecture.

The three pillars of CID security

You are always in control

CID never executes actions on its own. Every step the AI takes requires your approval. You stay in charge — the AI does the groundwork.

Data never leaves your environment

CID runs entirely within your own cloud environment. Company data never goes to external servers or shared infrastructure.

Your data never trains AI models

Your company data is never used to train AI models. What's yours stays yours — no exceptions.

Deploy in your own cloud

CID is available as a private deployment in your own Azure or cloud environment. Your IT department retains full control over infrastructure, access management, and data.

Runs entirely on your own Azure tenant or VPC
Fully GDPR-compliant — no data transfer to third parties
Your own encryption keys and identity provider (SSO/Entra ID)
Scales to your own SLA and retention policy

How CID handles your data

Encryption
TLS 1.2+ for data in transit · AES-256 for data at rest
Authentication
OAuth 2.0 for all integrations · role-based access control (RBAC) · SSO support (Entra ID / SAML)
GDPR
GDPR-compliant AI models only · data processing agreement available · data residency within the EU
Integrations
OAuth 2.0 with minimal scopes · your credentials are stored encrypted and never leave your environment
Retention & deletion
You define the retention policy · data can be fully deleted on request
Incident response
Structured notification procedure · data breach notification in line with GDPR requirements

Want to know more about our security approach?

We're happy to share our architecture documentation and data processing agreement, or discuss your specific security requirements.

Get in touch