TRUST & SECURITY
Built so your client data cannot leave.
PrivateNode is designed for firms whose regulator, insurer, and clients all expect a straight answer to one question: where does our data go? Here is the whole answer, in one place.
A single-tenant node, not a shared platform
Each firm gets its own dedicated server. Your documents, your vector index, your conversation history, and your audit trail live on that one machine and nowhere else. There is no shared database, no data commingling between clients, and no multi-tenant application layer to misconfigure.
EU/UK data residency
Your node runs in European data centres (Hetzner, Germany and Finland). Model inference runs on our provider’s United Kingdom region for the calls that read your question and the passages retrieved from your documents, and on its Finnish region for document indexing and answer checking. No US company processes your matter data.
Two US-incorporated suppliers sit at the edges, and we would rather name them than let you find them: our DNS provider, which resolves names and never sees traffic, and our payment processor, which handles billing through its Irish entity and never sees client content. A third, our optional web-search provider, receives question text when a firm switches that feature on, which is why it ships off by default. Everything else stays in UK-adequate jurisdictions end to end.
A control plane that only sees metadata
Your documents and your audit trail never leave your node. They are stored, indexed and searched on your own server, and we never receive them.
To answer a question, the text of that question does go out: to our model provider, a European company serving the regions named above, and to our own regulatory lookup service. When a document is first indexed, its text goes to that provider once, to be turned into a searchable form. That is true of any system built on hosted models. The difference is whether your supplier tells you.
Our observability service is metadata only: model names, token counts, latency, cost, and an anonymised client identifier, with no question or answer content, enforced in code at three independent points. Our Data Flow and Residency Statement maps every flow, including the ones above.
An audit trail your regulator can inspect
Every node keeps a full audit log on the server itself: who asked what, when, which sources were consulted, and what was answered. It is hash-chained, so alteration is detectable. If the SRA, FCA or ICO asks how AI is used in your practice, the evidence is on your own machine and under your control. A one-click export is in build; today the records are retrievable from the database on request.
Zero retention with AI providers
Model inference is ephemeral: our EU providers process prompts and discard them, and do not train on them. We select providers on that basis. We are in the process of executing data processing agreements that make it contractual rather than a matter of provider policy, and we will say so here when they are in place.
GDPR Article 28, as standard
You remain the data controller; PrivateNode acts as your processor. A Data Processing Agreement covering GDPR Article 28 (documented instructions, confidentiality, security measures, sub-processor transparency, and deletion on exit) is provided as part of onboarding, along with compliance documentation for your own risk assessment.
Certified infrastructure, honestly attributed
Our hosting provider, Hetzner, holds ISO 27001 certification for the data centres your node runs in. That certification belongs to the infrastructure layer, and we say so plainly: PrivateNode builds on certified hosting rather than claiming the certificate as its own.
Single-tenant node
EU/UK residency
Metadata-only control plane
On-server audit trail
Contractual zero retention
GDPR Art. 28 DPA
QUESTIONS FOR YOUR RISK ASSESSMENT?
We will walk your COLP, DPO, or compliance lead through the architecture and provide the documentation pack.
Book a 20-minute demoSee also our Privacy Policy and Terms of Service.