Security & privacy
Security and privacy for European research data.
Cauliflower is built for research teams that need governed access, GDPR-compliant data handling and reliable enterprise options — hosted in the EU, by design.
Data hosting & GDPR
EU-hosted by design.
Built in Hamburg and hosted entirely in the EU. Your research data is processed in European data centres under GDPR — customer data processing stays in the EU.
All infrastructure runs in EU data centres. Built in Hamburg, hosted in Frankfurt, Gävle and Dublin.
Data handling and processing designed to meet GDPR requirements end to end.
We sign a data processing agreement with every customer.
EU regions: Frankfurt, Germany (eu-central-1), Gävle, Sweden (eu-north-1) and Dublin, Ireland (eu-west-1). Customer data is processed in the EU.
You control retention. On request or contract end, data is deleted within 30 days and purged from backups within 90.
Access & governance
Control who can see, edit and share insights.
Give every team member the right level of access — across dashboards, public links and PowerPoint exports — and keep control of what gets shared beyond the team.
Invite the whole team — assign roles per project or workspace and change them anytime.
Enterprise security
Enterprise options for regulated teams.
For teams with strict IT, procurement and compliance requirements — single sign-on, isolated environments and the operational guarantees enterprise buyers expect.
Single sign-on (SSO)
Log in through your identity provider with SAML 2.0 — provision and de-provision centrally.
Audit logs
Track access, changes, shares and exports — a complete record for compliance reviews.
Private tenant
A dedicated, isolated environment for your organisation — separate from shared infrastructure.
On-premise
Deploy Cauliflower inside your own infrastructure when data must stay on your systems.
Custom integrations
Connect Cauliflower to your data stack and internal tools via API and custom connectors.
Dedicated TAM + SLA
A named technical account manager and a contractual service-level agreement.
AI & data handling
AI grounded in your research context.
The assistant answers from your research model and dashboards — not the open web — and every answer traces back to the exact source it came from.
Trust slipped 8 points among 18–34 since wave 2 — price perception is the main driver.
Brand Tracker 2026 → Trust by wave chart, filtered to age 18–34.
Answers come from your research model and dashboards — not the open web.
Every answer cites base size, filter and the exact chart it came from.
Findings live in the research model, not a disconnected chat log.
AI runs on OpenAI models via Microsoft Azure in an EU region — processing stays in the EU.
Your research data is not used to train Cauliflower models or the foundation models it runs on.
Security documents
Security documents available on request.
Everything procurement and IT need for review — shared under NDA on request. Tell us what you need and we'll send it over.
DPA / AVV
Our standard data processing agreement, ready to sign.
TOMs
Technical and organisational measures protecting your data.
NDA
Mutual non-disclosure agreement before we share sensitive detail.
Security one-pager
A concise summary of our security posture for quick review.
Subprocessors
The current list of subprocessors and what each one handles.
Contact security
Questions from IT, security or procurement? Talk to our team directly.
Need security details for procurement or IT?
Request our documents or book a demo — we'll walk your team through hosting, access and data handling in detail.
EU-hosted · GDPR-compliant · Answered within 2 business days