Skip to main content

Trust & Security

ContentCloud is designed for organizations that need privacy-conscious AI, EU-oriented deployment options, and clear operational boundaries. This page summarizes the controls and practices we emphasize across the current product ecosystem.

Last reviewed: 13 September 2026

Certification and security management

ContentCloud is operated by EWORX S.A., which holds ISO/IEC 27001 certification for its information security management system. Certification details and the current certificate can be provided during security review or procurement.

Security

  • • Encryption at rest and in transit; key and secrets management.
  • • Penetration testing and vulnerability remediation; reports available on request.
  • • Access logging and least‑privilege controls.

Data residency & retention

EU data centers by default. Retention windows are configurable per tenant, with export/delete supported to meet GDPR obligations.

Data use and AI providers

  • • Customer data is not used to train shared models.
  • • AI features are designed around traceability, review workflows, and human oversight.
  • • Product capabilities and provider choices may vary by deployment model and use case.

Product-specific trust boundaries

  • • CCBot is designed around approved content sources, citations, and configurable governance controls.
  • • Memory is designed around private-by-default raw capture, workspace boundaries, and governed promotion of reusable knowledge.
  • • Shared organizational value should come from validated artifacts and policies, not unrestricted access to raw user activity.

Infrastructure, hosting and sub‑processors

Managed ContentCloud deployments run on dedicated bare-metal servers provided by Hetzner Online GmbH in EU data centres (Germany and Finland). Hetzner supplies the physical infrastructure and does not operate the application or access customer content. Memory's EU-hosted sync runs on the same infrastructure.

On-premises and private-cloud deployments run entirely on infrastructure you control. The current sub-processor position for your specific deployment model, together with the DPA and any AI provider arrangements, is confirmed in writing during procurement — and we notify customers before adding a new sub-processor.

EU AI Act statement

ContentCloud products are general‑purpose content tools, not intended for high‑risk decision‑making. We commit to transparency (AI indicators & citations), human oversight, risk management, logging and post‑market monitoring.

Documents

  • • Data Processing Addendum (on request)
  • • Security overview (this page)
  • • Incident response summary (on request)
  • • Additional deployment and architecture details can be shared during pilot and procurement discussions.

What is self-serve and what is on request

ContentCloud is an evolving ecosystem, and some controls are product-specific or deployment-specific. Where a document, integration or operational detail is provided during solution design rather than self-serve, this page says so explicitly. Anything you need for a DPIA, security review or tender that is not published here can be requested directly.