Quick Summary
When evaluating AI software vendors, security and compliance teams require concrete facts rather than generic marketing promises. AISolutions AS provides complete transparency into where your data flows, how models are hosted, and how risk is architecturally mitigated across our AidEun and SalesQuote platforms.
Key Takeaway: All enterprise data processed by AISolutions AS stays strictly within the European Economic Area (EEA) in Norway East, governed by ISO 27001 standards, with zero data utilized for third-party LLM model training.
The Challenge
Enterprise adoption of Generative AI often stalls during IT security and legal review. Decision-makers face critical unanswered questions:
- Where is sensitive operational data processed and stored?
- Is proprietary business data exposed to public API endpoints or used to train public foundation models?
- How do system architectures defend against prompt injection and hallucinations in commercial workflows?
Vague vendor assurances increase regulatory exposure under GDPR and create unacceptable operational risks for enterprise leadership.
Our Architectural Solution & Safety Commitments
AISolutions AS addresses these concerns through precise technical architecture, contractual guarantees, and rigorous data governance policies.
1. Sovereign EEA Hosting & Data Residency
All AI inference and application workloads run within dedicated Azure OpenAI resources located in Microsoft's Norway East region.
- No Cross-Border Transfers: Your prompts, document extractions, search embeddings, and system outputs remain entirely inside the EEA.
- Dedicated Infrastructure: Workloads operate inside isolated Azure tenancies rather than shared public API endpoints.
- Prohibited Model Providers: We strictly prohibit the use of non-vetted or non-EEA foreign models in our production and evaluation pipelines.
2. Contractual Zero-Training Guarantee
A common vulnerability in enterprise AI procurement is the ambiguous use of customer data for vendor model training.
- No Model Training: Neither AISolutions AS, Microsoft, nor OpenAI can access your prompts or completions to train or fine-tune public or third-party models.
- Contractual Binding: This commitment is enforced both structurally via enterprise Azure contracts and contractually through our standard Data Processing Addendum (DPA).
3. Structural Hallucination & Prompt Injection Defenses
AI assistants should never operate as unmonitored decision-makers. We mitigate autonomous risk through strict architectural boundaries:
- Retrieval-Grounded Processing (RAG): AI agents answer directly from your uploaded content and internal system records rather than model memory, making outputs verifiable against source documents.
- Human-in-the-Loop Design: Commercial outputs—such as quotations generated in SalesQuote or outbound customer communications—require explicit human approval before execution.
- Tenant Isolation & Least Privilege: System permissions strictly mirror the signed-in user's credentials, preventing cross-tenant access or unauthorized data exposure.
4. Comprehensive Data Retention & Granular Deletion
Data privacy requires clear lifecycle management for every stored entity:
- Granular Schedules: Every database row, vector embedding, file snapshot, and chat cache is governed by a documented retention schedule overseen by our Security Lead.
- Configurable Lifespans: Enterprises can configure retention windows (e.g., chat histories from 30 days to 24 months) to meet internal compliance policies.
- Complete Erasure: When a record reaches its expiration date or an erasure request is executed, all derived data—including embeddings and cached copies—is permanently deleted.
Actionable Security Checklist for AI Evaluation
- Verify that your AI vendor processes data inside dedicated EEA cloud regions.
- Confirm contractual terms prohibiting the use of customer inputs for LLM training.
- Validate that human-in-the-loop workflows exist for high-impact commercial actions.
- Ensure vector embeddings are purged synchronously whenever source documents are deleted.
Next Steps
Review our complete compliance documentation, including our public Data Processing Addendum and supplier lists at aisolutions.no/dpa. To request an in-depth security briefing or customized compliance documentation for your procurement team, contact our technical team today at thore@aisolutions.no.


