New · We are an implementation partner for AgenticObjects: analytics agents that work on top of your data warehouse, starting with a 4-week pilot. See how the pilot works
SECURITY AND COMPLIANCE

Security and compliance: it starts with the architecture

Data security is the foundation of D-CAT projects and products. GDPR and KVKK (Turkish data protection law), enterprise security standards and the protection of personal data (PII) are part of that foundation.

PRINCIPLES

Three principles

We treat security not as a layer added later, but as the starting point of the architecture.

Data control stays with you

Depending on the deployment model, we work on-premises, in a private cloud, in a hybrid setup or in the cloud; your organization decides where data is processed. In Axoria Data Studio, the Privacy agent detects personal data fields before data reaches the model and transforms them while preserving their format, so the AI works with data whose statistical properties are preserved instead of real identity details.

Every step is auditable

Agent calls, model decisions and data access are logged. The question “Why did this result come out this way?” has a traceable, reproducible answer.

Enterprise standards

GDPR, KVKK and enterprise security policies are part of the design, and the architecture is updated as regulations change. Role-based access, row- and column-level authorization and encryption are at the core of our products.

INDEPENDENT CERTIFICATION

Our certificates

Information security, process maturity and public sector qualification are certified by independent bodies.

ISO/IEC 27001

Information security management system. Customer data, corporate assets and operational processes are subject to independent audit; it forms the basis of GDPR and KVKK compliance.

View the document (PDF)

SPICE · ISO/IEC 15504

Software process maturity: an international maturity assessment of development processes, disciplined quality and repeatable delivery. A standard recognized in public tenders.

View the document (PDF)

Public IT Authorization Certificate

Issued by the Presidency of the Republic of Türkiye, it authorizes us to provide IT services to public institutions. It is the legal basis for D-CAT projects in government agencies, state-owned enterprises and municipalities.

View the document (PDF)
REGULATION

GDPR and KVKK compliance

We design regulation-compliant architectures for our customers in Türkiye and Europe.

Business districts and the city skyline in Istanbul
Türkiye

KVKK compliance

KVKK, the Turkish Personal Data Protection Law, is the basis for enterprise data projects in Türkiye. D-CAT products are designed with an architecture that complies with it.

The Privacy agent in Axoria Data Studio detects personal data fields in the source database and transforms them while preserving their format: statistical properties are kept, and identity details never reach the model.

  • Turkish national ID number
  • IBAN and credit card numbers
  • First name, last name, phone, email
  • Address and date of birth
  • Sensitive health data
Server racks in a data center
Europe

GDPR and international standards

We build GDPR-compliant architectures for our Tallinn office in Estonia and for our international customers.

In regulated industries such as healthcare and finance, the industry's data sharing and privacy requirements are built into the project according to the deployment model.

  • Right to data portability
  • Right to be forgotten
  • Explicit consent management
  • Data breach notification processes
  • Rules for cross-border data transfers
TECHNICAL LAYER

The technical security layer

Encryption, authorization, logging and backup are defined by the deployment model and set up in line with the customer's security policy.

Encryption

Data is encrypted in transit and at rest; the method and key management are defined by the deployment model and your organization's policy.

Access control

Permissions are granted according to user roles.

  • Role-based access control (RBAC)
  • Row-level security (RLS)
  • Column-level masking
  • Single sign-on (SSO)

Monitoring and auditing

Access and activity logs are kept audit-ready.

  • Audit log
  • User activity report
  • Security incident response process

Deployment models

The architecture follows where the data and processing will run.

  • On-premises
  • Private cloud
  • Hybrid: data on-premises, processing in the cloud
  • Cloud-based (e.g. HealthCat)

Network security

Connections are restricted according to your network policy.

  • VPN and private endpoints
  • IP restrictions
  • Firewall policies

Backup and recovery

The backup and disaster recovery plan is defined by the deployment model, together with your business continuity targets.

ARCHITECTURE

AgenticObjects architecture: the model stays outside the data path

Three questions at a glance: where the application runs, what touches the data, and where the AI model sits.

Your data stays on your own serversThe AI only sees textWriting is technically impossible
AI model

Outside the frame. In the cloud or local. Only text goes out, never data; the model is fixed for each analysis.

AgenticObjects · on your own servers
Interface

App (end users) and console (administrators)

Processing

The agent runtime writes the narrative; the query engine calculates; FinalGuard checks at the gate

Semantic layer

One official, versioned definition for every measure

Records

Run and audit logs, roles, budgets

Two components that touch the data

SQL and SSAS gateways, both read-only. No writes, no copies; your passwords never reach us.

Customer data environment

Data warehouse (SQL) and SSAS cube. Data never leaves this environment.

Building queries, running queries, checking numbers, authorization decisions and spend control all stay outside the model.

AI

Responsible use of AI

When we build large language model and agent architectures, we give clear answers to three questions; AI use is always open to human oversight.

What data can the model access?

The data the model can access is limited by the deployment model; the connection runs on-premises, in a private cloud or in the cloud, and data sharing is logged.

How does the model decide?

Model outputs are explainable: the question “Why was this recommendation produced?” has an auditable answer.

What resources does the model use?

Every AI call is monitored and reported: which agent, which model, how many tokens and at what cost.

DOCUMENTS

Review our security documentation

We share data processing agreements, security protocols and audit documents on request.

Talk to an expert

Let's discuss our security architecture together at a technical level.

KVKK compliance project

Personal data discovery in your enterprise database: an end-to-end compliance project covering detection, classification, masking and transformation.

DOCUMENTS

Contact us for security documentation

Our team will get back to you about certificates, security documentation and deployment model options.