Security & privacy
Security and privacy for European research data.
Cauliflower is built for research teams that need governed access, GDPR-compliant data handling and reliable enterprise options – hosted in the EU, by design.
Data hosting & GDPR
EU-hosted by design.
Built in Hamburg and hosted entirely in the EU. Your research data is processed in European data centres under GDPR – customer data processing stays in the EU.
All infrastructure runs in EU data centres. Built in Hamburg, hosted in Frankfurt and Dublin.
Data handling and processing designed to meet GDPR requirements end to end.
We sign a data processing agreement with every customer.
EU regions: Frankfurt, Germany (eu-central-1) and Dublin, Ireland (eu-west-1). Customer data is processed in the EU.
Infrastructure & operations
How the platform is operated.
Operations, encryption and delivery in detail – for security reviews and procurement checks.
PostgreSQL 16.x on Amazon RDS, running Multi-AZ. Storage on EBS GP3, encrypted with AWS KMS under a Customer Managed Key – database, snapshots and backups included. Security patches are applied in defined maintenance windows.
The database is reachable only from private subnets, with no public IP addresses and no routing through an internet gateway. Access is granted via security groups rather than CIDR ranges; administrative access runs exclusively through AWS Systems Manager Session Manager.
TLS 1.3 as the default for all external and internal connections, TLS 1.2 as the minimum. Older protocol versions are disabled. Database connections are TLS-encrypted throughout, with certificate validation.
Credentials, API keys and certificates live in AWS Secrets Manager with automated rotation. They are injected at runtime – no secret sits in a repository, a container image or a configuration file.
Deployment and security testing
An automated, Terraform-based CI/CD pipeline. Infrastructure changes happen only as versioned code, with no manual access to production systems. Four checks run inside every deployment; findings of high severity or above fail the build.
Remediation deadlines in production
- Critical24 hours
- High7 days
- Medium30 days
Access & governance
Control who can see, edit and share insights.
Give every team member the right level of access – across dashboards, public links and PowerPoint exports – and keep control of what gets shared beyond the team.
Invite the whole team, assign roles and seats for the workspace, and change them at any time.
Enterprise security
Enterprise options for regulated teams.
For teams with strict IT, procurement and compliance requirements – single sign-on, isolated environments and the operational guarantees enterprise buyers expect.
Single sign-on (SSO)
Signing in through your identity provider is supported in principle. We agree the specifics as part of the offer.
Private tenant
A dedicated, isolated environment for your organisation – separate from shared infrastructure.
On-premise
Deploy Cauliflower inside your own infrastructure when data must stay on your systems.
Custom integrations
Connect Cauliflower to your data stack and internal tools via API and custom connectors.
Dedicated TAM + SLA
A named technical account manager and a contractual service-level agreement.
AI & data handling
AI grounded in your research context.
The assistant answers from your research model and dashboards – not the open web – and every answer traces back to the exact source it came from.
Trust slipped 8 points among 18–34 since wave 2 – price perception is the main driver.
Brand Tracker 2026 → Trust by wave chart, filtered to age 18–34.
Answers come from your research model and dashboards – not the open web.
Every answer cites base size, filter and the exact chart it came from.
Findings live in the research model, not a disconnected chat log.
AI runs on OpenAI models via Microsoft Azure in an EU region – processing stays in the EU.
Your research data is not used to train Cauliflower models or the foundation models it runs on.
Where the models run
Inference on external models runs exclusively through Microsoft Azure OpenAI Service in the Sweden Central region, as an EU Data Zone deployment – so processing demonstrably stays inside the EU data zone. Use of your data to train or improve models is contractually excluded. Cauliflower's own models run in the same AWS environment as the platform; data does not leave our own infrastructure there.
Where AI acts
Transparency about what is generated automatically.
Four places in Cauliflower work with AI. Here is which – and what stays in your hands.
Asks respondents targeted follow-up questions while the survey is still open.
Maps open answers to your codebook, detects sentiment and summarises topics. The codebook stays yours.
Drafts a takeaway for a chart. You edit it, keep it or discard it.
Answers from your research model, not the open web. Every answer points back to its source.
Security documents
Security documents available on request.
Everything procurement and IT need for review – shared under NDA on request. Tell us what you need and we'll send it over.
DPA / AVV
Our standard data processing agreement, ready to sign.
TOMs
Technical and organisational measures protecting your data.
NDA
Mutual non-disclosure agreement before we share sensitive detail.
Security one-pager
A concise summary of our security posture for quick review.
Subprocessors
The current list of subprocessors and what each one handles.
Contact security
Questions from IT, security or procurement? Talk to our team directly.
Need security details for procurement or IT?
Request our documents or book a demo – we'll walk your team through hosting, access and data handling in detail.
EU-hosted · GDPR-compliant · Answered within 2 business days