Skip to content

Security & privacy

Privacy is not an option.
It is the starting point.

The question “where do our documents go?” has only one good answer: nowhere. DeepView was designed to be installed and used by you, on your premises. This page sets out precisely what that implies, and what it does not.

Our four principles

Verifiable commitments, not intentions

1. Your documents stay with you

The documents, what DeepView draws from them, the conversations and the accounts: everything is stored on your company's machine. None of it is copied over to us.

2. Nothing is reachable without identification

Nobody reaches anything without having identified themselves, and every action is authorised according to that person's role on the project concerned.

3. Your data trains nobody

Not us, not a third party. Your documents serve only to answer your own questions, at the moment they are asked.

4. You know what goes out, and you authorise it

The only thing that can go out is what is submitted to the AI model, and you are the one who chooses the architecture, below.

Where your data goes

What is stored, and where

The table below deliberately contains no grey areas.

DataWhere it is keptWho can reach it
Your documentsIn your environmentAuthorised users of the project concerned
The information extracted from your documentsIn your environmentDeepView only, for analysis and information retrieval
The knowledge baseIn your environmentDeepView only
User conversationsIn your environmentOnly the users concerned
User accounts and credentialsIn your environmentNobody: passwords are never readable, including by our teams
The information sent to the AI engineIn your environment, or with the provider you have chosenAccording to the architecture you have selected

The last row is the only one that calls for a decision on your part: that is the subject of the next chapter.

The sensitive point, addressed head-on

The choice of AI model is yours

To write an answer, an extract of your documents has to be submitted to an AI model. That is the only moment when anything can go out. We do not impose it: you choose the architecture.

No model is imposed by the product: DeepView addresses whichever one you designate, which is what lets it run on a site entirely cut off from the outside if you choose architecture 1.

1 — Full control

A local, open-source model

The DeepView server and an open-source LLM both run on your own infrastructure. Nothing ever leaves your premises, at any point.

2 — You keep your contract

The LLM provider you already use

The server stays on your infrastructure and connects to the LLM provider or providers you have already contracted with. DeepView does not need a powerful model to work well.

3 — We provide the model

A secure environment hosted in Europe

The server stays on your infrastructure; the call to the model goes to a secure environment hosted in Europe and provided by Alister AI. The communication is encrypted.

Who sees what

Compartmentalisation follows your organisation

The accounts are yours

Users are created and removed by whoever administers the system on your side. Passwords are never stored in clear text: even we could not read them.

Every project is compartmentalised

Documents belong to a project. A person sees only the projects they are part of: the others do not exist for them.

Conversations are private

What you ask belongs to you alone. A colleague on the same project has no access to it, and neither does the administrator.

Transparency

We believe a relationship of trust calls for complete transparency

A vendor claiming to receive nothing at all is rarely being transparent. DeepView is designed to keep exchanges with our services to the strict minimum. We state clearly which information may reach us and which always stays in your environment.

What reaches us
  • The validity of your subscriptionA regular check that the solution is properly covered, along with its version and scope.
  • Version informationEnough to identify whether an update is available.
  • Technical health indicatorsLimited to diagnostics and service improvement, with no document content and no business data.
What never reaches us
  • Your documents, and their content
  • The questions your users ask
  • The answers DeepView produces
  • The names of your projects and files
  • The identity of your users
  • The knowledge base built from your documentation

In short: what we know is limited to the checks required for the application to work properly, and we know nothing about your infrastructure, your documents, your knowledge or your exchanges.

What we hand over to your IT teams

  • The detailed diagram of the installation and its exchanges
  • Installation and hardening documentation
  • The response to your vendor questionnaire
  • The list of components used and their licences
  • The contractual commitments on your data

Compliance

GDPR: a simple position

Because the software runs on your machines and we do not access its content, any personal data present in your documents remains entirely under your responsibility and your control.

In concrete terms: we host nothing, we do not read your documents, and nothing is transferred to us. The precise terms (including for troubleshooting that requires temporary access) are set out in the contract.

Security questions

The objections we are given

Can you access our installation?
No. The software provides no access for our own use. If you want us to step in for troubleshooting, you are the one who opens access to us, for the period you set, under your own rules.
Are our documents used to train or improve your product?
No, since they never reach us. Our improvements rest on our own research, on automatic incident reports, and on the feedback you choose to send us.
What does the administrator see?
The administrator manages users, access rights and projects. Conversations stay private and are not reachable from the administration interface. As with any application installed in your infrastructure, system administrators also retain the technical access that comes with their responsibilities: the scope of what they can do falls under your own governance and authorisation rules.
What happens if the subscription stops?
Search and question functions are no longer available, but no data is deleted. Your documents, the knowledge base built from them and the associated information all stay in your environment, and become immediately available again when the subscription is reactivated.
Has the product been audited?
We claim no certification we do not hold. We do, however, make available the information your security assessments require, and we support audits or tests carried out by your teams or your providers.
How are vulnerabilities handled?
Fixes are shipped as new versions, which install without touching your data. Any reported vulnerability is handled according to our security incident process.

A question this page doesn't cover?

Write to us: security topics are handled directly by the team that builds the product, with no sales intermediary.