Your strategic content deserves infrastructure that matches.

Paul is built for organisations that take data seriously. EU hosting, strict no-training policy, organisation-level isolation — here are the concrete commitments you can audit.

01 · Data sovereignty

Exclusively EU-hosted infrastructure

Our entire infrastructure runs within the European Union:

  • Database & storageSupabase EU (Frankfurt / Paris regions)
  • Application serverRailway EU (Western Europe region)
  • Collaborative editingWebSocket server hosted in Europe

No customer data leaves the EU for application processing. Inference requests to model providers are made with explicit training opt-out flags on the provider side.

02 · No model training

Your data never trains a model

We never reuse your templates, prompts, presentations or metadata to train or fine-tune any model, whether internal or operated by a partner.

All calls to partner LLMs (OpenAI, Anthropic, Mistral) are made with data_retention and training_opt_out flags enabled. Request logs are retained strictly for billing and observability purposes, then purged according to our retention policy.

03 · Isolation

Strict organisation-level isolation

Each customer organisation has a dedicated isolated space enforced at the database level via Postgres Row Level Security. No query can cross organisation boundaries — by design.

Roles (administrator, editor, external consultant) are managed granularly and audited. A user removed from an organisation loses access immediately, with no residual access.

04 · Technical security

The technical foundations

  • Encrypted in transitTLS 1.2+ everywhere, strict HSTS with preload
  • Encrypted at restAES-256 on the database and object storage
  • Security headersStrict CSP, X-Frame-Options DENY, strict-origin Referrer-Policy
  • AuthenticationSupabase Auth (ES256-signed JWTs), short sessions, automatic rotation
  • Rate limitingOn all public surfaces (sign-up, login, API)
  • ObservabilityError tracking, access logging, automated alerting

An internal security audit covering 13 cybersecurity domains was conducted in April 2026; priority fixes were applied across all environments.

05 · GDPR compliance

Your rights, enforceable on request

  • Right of accessFull data export on request at contact@logitopia.fr
  • Right to erasurePermanent deletion of your organisation and all its content within 30 days
  • PortabilityYour templates and presentations can be exported in open formats (.pptx, .pdf) with no lock-in
  • Sub-processorsExhaustive list of technical sub-processors provided on request as part of a DPA

Paul is published by Logitopia SAS, a French legal entity subject to GDPR and French law.

06 · Roadmap

What we are building for enterprise accounts

  • Enterprise SSOMicrosoft Entra (Azure AD), Google Workspace, Okta via SAML 2.0 / OIDC
  • SCIMAutomated user and role provisioning
  • Dedicated audit logExportable audit trail for internal compliance
  • CertificationsISO 27001 and SOC 2 Type II certification in progress

These features are available on request as part of an Enterprise engagement. Let's discuss your requirements during a personalised demo.

A specific question about your compliance context?

We respond individually to every RFP, security questionnaire, or DPA. Book a demo — we will take the time to understand your requirements.