Your data stays with you
Contineo is built so your company's content stays safely in your database and storage. AI is only a helper — not a place your data goes.
Data in your database
Content lives in your MongoDB and storage, isolated per tenant. It isn't public and isn't indexed by the public internet.
No public AI
We never use public consumer AI. Public models are not trained on your data.
AI is only a helper
The language model answers strictly from retrieved passages of your content (RAG) and attaches a source citation.
You choose the mode
Cloud with EU residency and a zero-retention agreement, or fully on-prem where data never leaves your infrastructure. Same application, different configuration.
Where your text actually goes
Not where the data rests, but where it gets processed. That distinction decides whether you pass procurement — and most vendors leave it out.
1 · Data at rest in the EU
Database, indexes and backups sit in the EU. Calling AI models abroad is permissible under a processing agreement and standard contractual clauses.
ordinary commercial deployment
2 · Nothing leaves the EU
The models run in the EU too — including the questions your people type. Not a GDPR requirement, but it does appear in tender conditions.
public sector, larger companies
3 · Nothing leaves the perimeter
The whole system runs on your infrastructure. Without outbound connectivity, if required.
classified material, closed networks
Level 1 is legally sound — GDPR does not forbid transfers outside the EU, it conditions them. But when a tender says “data must not leave the EU”, that is an organisational requirement no contract can satisfy. A vendor who can only offer level 1 gets excluded on form, not on merit.
Modes we can deploy
The mode is a property of your organisation, not of our edition. Same application, different configuration — and a disallowed combination simply refuses to start.
| Mode | What it means | Embedding | Rerank | Generation |
|---|---|---|---|---|
| eu-data | Data in the EU, processing may be outside | MongoDB Atlas | MongoDB Atlas | Claude API |
| eu-full | No text leaves the EU | own service | own service | own model |
| on-prem | Everything on your infrastructure | own service | own service | own model |
| air-gap | Closed network, no outbound connectivity | own service | own service | own model |
The second question: does it run for us alone?
The mode above says which country processes your text. It does not say whether that processing happens on a machine reserved for you, or on a service that is serving other customers at the same moment. These are two independent questions and the system checks both.
| Level | What it means | When it makes sense |
|---|---|---|
| T1Shared | Shared infrastructure. Your documents are separated by access rules, but the model processing them also serves others. | standard commercial deployment, small and mid-sized companies |
| T2Dedicated | Embedding, reranking and generation run on instances that serve no one else. Your text never passes through a shared process. | banks, large enterprises, sensitive internal policies |
| T3Disconnected | Dedicated, plus no outbound connectivity. Requires air-gap mode — otherwise the disconnection exists only on paper. | classified material, closed networks |
Levels combine with modes; they are not steps on a single scale. A shared service can run entirely inside the EU (T1 + eu-full), and a dedicated instance can sit anywhere (T2 + global). And one thing most vendors will not say out loud: a dedicated cloud account is not dedicated hardware. That is why Claude via AWS Bedrock does not pass at level T2 even though it runs in Frankfurt — the model there serves everyone else too.
Where processing happens — including what we are still verifying
Every row is backed by the vendor's own public documentation, not by an estimate. Components processing outside the EU are not used in the eu-full, on-prem and air-gap modes — a profile with such a combination refuses to start.
| Component | Provider | Processing location | Basis |
|---|---|---|---|
| Database, indexes, backups | MongoDB Atlas | EU (Frankfurt) | region chosen when creating the cluster |
| Hybrid search | mongot in cluster | EU (Frankfurt) | computed inside the cluster |
| Reranking | $rerank (Voyage) | outside the EU (US) | stated in Atlas project settings |
| Embedding | Atlas Automated Embedding | outside the EU (US) | MongoDB subprocessor list: Google LLC, United States |
| Answer generation | Anthropic Claude (direct API) | outside the EU (US) | processed in US infrastructure |
| Answer generation | Claude via AWS Bedrock / Vertex AI | EU (Frankfurt, Ireland, Paris) | region chosen at deployment |
| Embedding, rerank, generation | own services (on-prem) | your infrastructure | runs at your site |
Why we spell this out in such detail. Because someone in procurement will ask. Most vendors state “data in the EU” and stay silent about where the model runs — yet that is exactly where the question and the retrieved passages go. Every row above is backed by the vendor's own documentation, and if the situation changes, so does this table.
This page is a technical description of data flows, not a legal assessment. For a specific deployment we recommend review by a data protection specialist.
User management and sign-in
Users sign in via your existing SSO and see exactly what they're entitled to — with no manual account creation.
SSO and single sign-on
Sign in via OAuth/OIDC — Microsoft Entra ID, Google Workspace, your own accounts or another identity provider. One canonical session across the whole system.
Automatic account provisioning
Users, roles and groups are created automatically from a connected CRM / identity source. No manual account management — onboarding and offboarding happen on their own.
Multi-tenant access
A hierarchy of organisations (headquarters → regional → local units). Public content is visible to everyone; internal only to members of that unit, with per-document sharing.
Security at query level
An access right is a mandatory filter derived from the server-side session (default-deny). It is applied before the language model — it cannot be bypassed by a prompt. Audit on every change.
Supported identity providers
Ready to get your content at your fingertips?
We'll show you Contineo on your own sources.
Get in touchoffice@contineo.app