For procurement, ITand the works council.
Single sign-on, SCIM, a data processing agreement with subprocessor annex, usage policies and an admin area that never shows content — all on every plan, without an enterprise surcharge.
We usually reply within two working days
Identity from your directory
SSO via SAML or OIDC, accounts created and deactivated via SCIM, two-factor requirement by switch.
An organisation's security settings: two-factor requirement, SSO, SCIM, IP allowlist and session length, all switched on; only the owner changes them.
Admins see usage, never content
The usage dashboard aggregates — chats, files and prompts stay with the person.
Usage dashboard for administrators: members with chats and tokens, the Content column is empty — administrators never see chat content.
Your directory stays the truth
No second password, no manual creation: access comes from your identity provider and leaves with it.
Single sign-on
SAML 2.0 and OIDC — sign-in via your identity provider, bound to your domain.
SCIM 2.0
Create accounts automatically, assign groups, deactivate on exit — including ending running sessions.
Two-factor required
One switch for the whole organisation; anyone without it set up is guided at the next sign-in.
Sessions and network
Session length between 1 hour and 30 days, IP allowlist, organisation-wide sign-out at the push of a button.
Governance that lives in the product
Who may do what, who checked it, what is in use — in the platform, not in a spreadsheet beside it.
AI usage policy
Your policy, versioned, acknowledged by every person — with proof for the documentation.
Approval lifecycle
Agents and skills are unreviewed, approved, flagged or disabled; connections have allow-lists per tool.
Audit log and register
Every setting, approval and role change recorded; the AI system register lists what is in use.
Inventory of agents with approval status: quote assistant approved, research assistant unreviewed, termination helper flagged; below it the usage policy with 24 of 26 acknowledgements.
Contract, privacy, evidence
What legal needs is attached — and what the works council asks is a product principle.
- Data processing agreement under Art. 28 GDPR with a named subprocessor annex; changes with customer notice and objection period
- Processing by default exclusively with European providers in the EU — sovereignty level per organisation, changed only by the owner
- Retention periods per organisation, hard delete, data export
- Invoices as e-invoices under EN 16931, prices net per user and month
- Security questionnaire: we answer with the status from the trust center
- No training on your data — not by us, and contractually secured in the default model path
The works-council argument
Admins see aggregated usage — never chats, files or prompts. There is no "view as user" mode. Temporary chat and immediate deletion are standard.
Processing locations and EU sovereigntyRollout in three steps
From pilot to rollout, without project overhead.
- 01
Pilot with one department
Create the organisation, connect SSO, one department with a knowledge area and two skills — first value in days.
- 02
Policy and approvals
Publish the usage policy, approve agents and connections, take groups over from the directory.
- 03
Rollout with evidence
Extend seats, academy course for AI literacy under Art. 4 AI Act, usage in the dashboard — without content.
Let us talk about your requirements
Demo, questionnaire or DPA draft — one request is enough.