1. EU hosting and encryption
All data processing happens on servers in the EU. Data is encrypted in transit (TLS) and at rest, and access to production systems is restricted and logged.
2. PII scrubbing before AI
Before anything is sent to an AI model, personally identifiable information is removed from the payload. CPR numbers, personal names, Danish IBANs, emails and phone numbers are replaced with reference tokens (e.g. [PERSON_REF_001]) that can only be translated back inside our own infrastructure. The AI model never sees the original values.
Invoice PDFs follow the same principle. Requests are routed exclusively to zero-data-retention AI providers that neither store nor train on the content, and the fields the model returns are scrubbed in our PII vault before they are used further in the system.
3. Encrypted credential vault
Access tokens and credentials for your integrations are stored encrypted in a dedicated vault (sealed boxes). They are decrypted only at the moment an action requires them, and are never exposed to AI models or in logs.
4. Approval-first
TalVagt proposes — you approve. By default the agent posts, sends or changes nothing without your explicit approval. If you choose to enable automation, it happens only within the rules and limits (e.g. spend caps and confidence thresholds) you have configured yourself.
5. Audit trail
Every action — proposal, approval, posting and change — is recorded in an audit trail with a timestamp and actor, so you and your accountant can always trace what happened and why.
6. Access control
Each customer's data is isolated at the database level (row-level security), so one organisation can never access another's data. Internally, access to production data is limited to what is strictly necessary and is logged.
7. Backup and recovery
Data is backed up regularly within the EU, and we maintain recovery procedures for outages so your accounting data can be restored.
8. Incident response
We maintain an incident-response process for security events. If a personal-data breach is identified, we notify affected customers (as controllers) without undue delay and at the latest within 72 hours, in line with GDPR.
9. Vulnerability reporting
Found a vulnerability? Email contact@talvagt.com(mark the message “Security”). We acknowledge receipt and work with you toward a responsible fix.
10. Certifications
We operate according to the principles described by recognised security standards. A formal certification status will be stated here as it is achieved — we only list certifications we actually hold.
11. GDPR and Data Processing Agreement
TalVagt is a data processor for your accounting data and processes it on your instruction via a Data Processing Agreement (DPA) made available to business customers. See our privacy policy for the full legal detail on processing, retention and your rights.