Security & privacy

Security and privacy for European research data.

Cauliflower is built for research teams that need governed access, GDPR-compliant data handling and reliable enterprise options – hosted in the EU, by design.

EU-hostedGDPR-compliantDPA availableSSO for Enterprise
100%EU-hostedFrankfurt · Dublin
GDPRCompliant handlingDPA / AVV available
SSOSingle Sign-onEnterprise-Option
EncryptedIn transit & at restTLS 1.2+

Data hosting & GDPR

EU-hosted by design.

Built in Hamburg and hosted entirely in the EU. Your research data is processed in European data centres under GDPR – customer data processing stays in the EU.

Data residency
EU only
European Union
Cauliflowereu-central-1
Data Encrypted Backups
Frankfurt · DublinISO 27001 data centres
Customer data processing stays in the EU.
Encrypted at restTLS 1.2+ in transit
100% EU hosting

All infrastructure runs in EU data centres. Built in Hamburg, hosted in Frankfurt and Dublin.

GDPR-compliant

Data handling and processing designed to meet GDPR requirements end to end.

AVV / DPA available

We sign a data processing agreement with every customer.

Data processing regions

EU regions: Frankfurt, Germany (eu-central-1) and Dublin, Ireland (eu-west-1). Customer data is processed in the EU.

100% EU hostingGDPRAVV / DPAFrankfurt · DublinEncryption at rest & in transit

Infrastructure & operations

How the platform is operated.

Operations, encryption and delivery in detail – for security reviews and procurement checks.

Database & encryption

PostgreSQL 16.x on Amazon RDS, running Multi-AZ. Storage on EBS GP3, encrypted with AWS KMS under a Customer Managed Key – database, snapshots and backups included. Security patches are applied in defined maintenance windows.

Network & administrative access

The database is reachable only from private subnets, with no public IP addresses and no routing through an internet gateway. Access is granted via security groups rather than CIDR ranges; administrative access runs exclusively through AWS Systems Manager Session Manager.

Transport encryption

TLS 1.3 as the default for all external and internal connections, TLS 1.2 as the minimum. Older protocol versions are disabled. Database connections are TLS-encrypted throughout, with certificate validation.

Secrets management

Credentials, API keys and certificates live in AWS Secrets Manager with automated rotation. They are injected at runtime – no secret sits in a repository, a container image or a configuration file.

Deployment and security testing

An automated, Terraform-based CI/CD pipeline. Infrastructure changes happen only as versioned code, with no manual access to production systems. Four checks run inside every deployment; findings of high severity or above fail the build.

Software composition analysisContainer image scanningInfrastructure-as-code scanningSecret scanning

Remediation deadlines in production

  • Critical24 hours
  • High7 days
  • Medium30 days

Access & governance

Control who can see, edit and share insights.

Give every team member the right level of access – across dashboards, public links and PowerPoint exports – and keep control of what gets shared beyond the team.

Access: role and seatRole + seat
Admin
Editor seat
Viewer seat
View dashboards
Edit & analyse
Share pages & public links
Manage members, roles & seats
Allowed Not permittedAdmin is the organisational role. Editing needs an editor seat, admins included. Viewer seats are free.
Public sharing, controlled
beta.cauliflower.ai/shared/brand-q3
Password protected
Up to 50 dashboards in one link
Optional expiry dateAug 12
Team collaboration

Invite the whole team, assign roles and seats for the workspace, and change them at any time.

+9
12 members · 3 roles
RolesPermissionsViewer / editorTeam collaborationPublic linksPassword protection

Enterprise security

Enterprise options for regulated teams.

For teams with strict IT, procurement and compliance requirements – single sign-on, isolated environments and the operational guarantees enterprise buyers expect.

Single sign-on (SSO)

Signing in through your identity provider is supported in principle. We agree the specifics as part of the offer.

Private tenant

A dedicated, isolated environment for your organisation – separate from shared infrastructure.

On-premise

Deploy Cauliflower inside your own infrastructure when data must stay on your systems.

Custom integrations

Connect Cauliflower to your data stack and internal tools via API and custom connectors.

Dedicated TAM + SLA

A named technical account manager and a contractual service-level agreement.

AI & data handling

AI grounded in your research context.

The assistant answers from your research model and dashboards – not the open web – and every answer traces back to the exact source it came from.

Cauliflowerresearch agent
grounded
How has trust developed in the young target group?

Trust slipped 8 points among 18–34 since wave 2 – price perception is the main driver.

n=812wave 3age 18–34
Sourcetraceable

Brand Tracker 2026 → Trust by wave chart, filtered to age 18–34.

Ask anything about this study…
Grounded in your context

Answers come from your research model and dashboards – not the open web.

Source-linked & traceable

Every answer cites base size, filter and the exact chart it came from.

No isolated chat histories

Findings live in the research model, not a disconnected chat log.

OpenAI models on Azure · EU

AI runs on OpenAI models via Microsoft Azure in an EU region – processing stays in the EU.

Not used to train models

Your research data is not used to train Cauliflower models or the foundation models it runs on.

Where the models run

Inference on external models runs exclusively through Microsoft Azure OpenAI Service in the Sweden Central region, as an EU Data Zone deployment – so processing demonstrably stays inside the EU data zone. Use of your data to train or improve models is contractually excluded. Cauliflower's own models run in the same AWS environment as the platform; data does not leave our own infrastructure there.

GroundedTraceableEU-processedNo training on your data

Where AI acts

Transparency about what is generated automatically.

Four places in Cauliflower work with AI. Here is which – and what stays in your hands.

Surveybot: follow-ups in a running survey

Asks respondents targeted follow-up questions while the survey is still open.

Text analysis: coding, sentiment, summaries

Maps open answers to your codebook, detects sentiment and summarises topics. The codebook stays yours.

Smart Captions: chart takeaways

Drafts a takeaway for a chart. You edit it, keep it or discard it.

Research agent: answers from your model

Answers from your research model, not the open web. Every answer points back to its source.

Security documents

Security documents available on request.

Everything procurement and IT need for review – shared under NDA on request. Tell us what you need and we'll send it over.

DPA / AVV

Our standard data processing agreement, ready to sign.

Request →

TOMs

Technical and organisational measures protecting your data.

Request →

NDA

Mutual non-disclosure agreement before we share sensitive detail.

Request →

Security one-pager

A concise summary of our security posture for quick review.

Request →

Subprocessors

The current list of subprocessors and what each one handles.

Request →

Contact security

Questions from IT, security or procurement? Talk to our team directly.

Need security details for procurement or IT?

Request our documents or book a demo – we'll walk your team through hosting, access and data handling in detail.

EU-hosted · GDPR-compliant · Answered within 2 business days