Skip to main content

Trust & Security

Built for confidential
patent work.

Wunder IP runs on 100% European infrastructure. Below you'll find every guarantee, control, sub-processor and compliance reference patent attorneys ask for during procurement.

100% European infrastructure · No AWS · No Azure · No US cloud hosting

What sets us apart

GDPR-compliant is not automatically data-sovereign.

Many vendors advertise „GDPR compliant" while running on US hyperscalers under the hood. That gives US authorities CLOUD Act access, even to client data stored in Europe. The CJEU made this explicit in „Schrems II" (C-311/18). We chose to solve the problem at its root.

Common in the AI market

  • EU hosting on AWS, Azure or GCP
  • Standard Contractual Clauses against the CLOUD Act
  • Reliance on the EU-US Data Privacy Framework

At Wunder

  • Hosting with European providers (Hostinger, Hetzner, Scaleway)
  • Language models on European infrastructure (Mistral, DeepSeek, GLM, Qwen, Llama, GPT-OSS)
  • Confidential client data stays in the EU; US providers optional, for non-sensitive tasks only
More on data sovereignty

Schrems II, CLOUD Act, Schrems III, and how we solve it.

Our commitment

Your intellectual property deserves the highest protection.

Fully GDPR-compliant and built to meet § 203 StGB professional-secrecy requirements, for patent attorneys handling sensitive client data every day.

Your data, prompts, and AI outputs are:

Not available to other customers
Stored and processed exclusively on European infrastructure by default
Not used to improve or train any AI models
Not used to improve any third-party products or services

Compliance

GDPR

GDPR

EU Data Protection Regulation

ISO
27001

ISO 27001:2022

Certified infrastructure providers

§ 203 StGB

Designed for professional secrecy

Controls

Security Controls

All controls active

Updated 07/2026

Infrastructure security

ISO 27001 certified data centers in Germany, Finland & France
TLS 1.2+ encryption for all data in transit
AES-256 encryption at rest
Self-hosted observability tools (no third-party telemetry)
Redundant infrastructure with 99% target availability
Encrypted backups & disaster recovery plan

Data protection

No data used for AI model training
No third-party data sharing for marketing or analytics
Data export on request (JSON, machine-readable)
Account deletion: 7 days from live systems, 30 days from backups
Strict tenant separation (logical & database-level)
Audit logs for all data modifications (append-only)

Access control

Passwordless OTP authentication
Multi-factor authentication (MFA) available
Role-based access control (RBAC) with least-privilege defaults
No passwords stored, authentication via certified identity provider
Time-limited sessions (token expiry)
Cookieless analytics; advertising cookies only with consent

Compliance

GDPR compliant by design
Designed for § 203 StGB professional-secrecy requirements
ISO 27001 certified providers
EU law jurisdiction (Munich, Germany)
Bilingual DPA (DE/EN) per Art. 28 GDPR
Personal data breach notification within 72 hours

Data path

Subprocessors

The following providers process data on our behalf. By default, all confidential matters stay on European infrastructure. Transactional emails are delivered via a US provider; optional frontier models are used through OpenRouter only when the user explicitly opts in for non-sensitive matters, protected by EU Standard Contractual Clauses and the EU-US Data Privacy Framework.

Primary infrastructure (European, default)

SubprocessorPurposeLocationSafeguards
HostingerEuropean VPS hostingGermany (EU)EU jurisdiction · GDPR
HetznerApp hosting, databases & document processingGermany & Finland (EU)EU jurisdiction · GDPR
ScalewayAI inference & embeddingsFrance (EU)EU jurisdiction · GDPR
tensorx.aiEU LLM routing (when enabled)Ireland (EU)EU jurisdiction · GDPR

US subprocessors (email & optional frontier models)

SubprocessorPurposeLocationSafeguards
ResendTransactional email deliveryUSAEU SCCs · EU-US Data Privacy Framework
OpenRouterOptional frontier models (OpenAI, Anthropic, Google) – opt-in, non-sensitive matters onlyUSAEU SCCs · EU-US Data Privacy Framework
Data sovereignty & Schrems II in detail

Documents & evidence

Resources

Documents

Data Processing Agreement (DPA / AVV)

Bilingual contract (DE/EN) per Art. 28 GDPR, including TOMs and approved sub-processors

request a copy

Questions from procurement?
We have the answers.

Security questionnaire, DPA, or a deep-dive on data sovereignty — reach out and we'll respond quickly and concretely.