Futureway
Enterprise

For procurement, ITand the works council.

Single sign-on, SCIM, a data processing agreement with subprocessor annex, usage policies and an admin area that never shows content — all on every plan, without an enterprise surcharge.

We usually reply within two working days

Identity from your directory

SSO via SAML or OIDC, accounts created and deactivated via SCIM, two-factor requirement by switch.

An organisation's security settings: two-factor requirement, SSO, SCIM, IP allowlist and session length, all switched on; only the owner changes them.

Admins see usage, never content

The usage dashboard aggregates — chats, files and prompts stay with the person.

Usage dashboard for administrators: members with chats and tokens, the Content column is empty — administrators never see chat content.

Identity

Your directory stays the truth

No second password, no manual creation: access comes from your identity provider and leaves with it.

Single sign-on

SAML 2.0 and OIDC — sign-in via your identity provider, bound to your domain.

SCIM 2.0

Create accounts automatically, assign groups, deactivate on exit — including ending running sessions.

Two-factor required

One switch for the whole organisation; anyone without it set up is guided at the next sign-in.

Sessions and network

Session length between 1 hour and 30 days, IP allowlist, organisation-wide sign-out at the push of a button.

Governance

Governance that lives in the product

Who may do what, who checked it, what is in use — in the platform, not in a spreadsheet beside it.

AI usage policy

Your policy, versioned, acknowledged by every person — with proof for the documentation.

Approval lifecycle

Agents and skills are unreviewed, approved, flagged or disabled; connections have allow-lists per tool.

Audit log and register

Every setting, approval and role change recorded; the AI system register lists what is in use.

Inventory of agents with approval status: quote assistant approved, research assistant unreviewed, termination helper flagged; below it the usage policy with 24 of 26 acknowledgements.

Contract & privacy

Contract, privacy, evidence

What legal needs is attached — and what the works council asks is a product principle.

  • Data processing agreement under Art. 28 GDPR with a named subprocessor annex; changes with customer notice and objection period
  • Processing by default exclusively with European providers in the EU — sovereignty level per organisation, changed only by the owner
  • Retention periods per organisation, hard delete, data export
  • Invoices as e-invoices under EN 16931, prices net per user and month
  • Security questionnaire: we answer with the status from the trust center
  • No training on your data — not by us, and contractually secured in the default model path

The works-council argument

Admins see aggregated usage — never chats, files or prompts. There is no "view as user" mode. Temporary chat and immediate deletion are standard.

Processing locations and EU sovereignty
Rollout

Rollout in three steps

From pilot to rollout, without project overhead.

  1. 01

    Pilot with one department

    Create the organisation, connect SSO, one department with a knowledge area and two skills — first value in days.

  2. 02

    Policy and approvals

    Publish the usage policy, approve agents and connections, take groups over from the directory.

  3. 03

    Rollout with evidence

    Extend seats, academy course for AI literacy under Art. 4 AI Act, usage in the dashboard — without content.

Let us talk about your requirements

Demo, questionnaire or DPA draft — one request is enough.

This website uses no cookies and builds no user profiles — which is why there is no cookie banner. Our anonymous reach measurement runs on our own servers in Germany, with no analytics service involved.

Learn more