Trust centre

How Caicle handles your data

Hosting, data flows, subprocessors, the DPA, AI Act obligations, isolation and the agent sandbox. Written for the person who has to sign off.

Hosting

The platform, its database and the agent sandbox run on servers in EU data centres operated by a European provider. Backups stay in the EU. The provider is listed in the subprocessor register and in your DPA.

Data flows

Three kinds of data move through Caicle, and they move differently.

  1. 01

    Account and workspace data

    Your users, settings, profiles and pipeline. Stored in the EU.

  2. 02

    Company research data

    Fetched from public sources and the company's own filings. Stored in your tenant.

  3. 03

    AI inference

    Prompts and research context are sent to a model provider to generate scores, summaries and plans. See the subprocessor register. Bring your own model key on any plan.

Subprocessors

PurposeProviderLocationSafeguardSince
Hosting, database and agent sandboxEU hosting providerEUDPA, ISO 270012026
Email deliveryTransactional email providerEUDPA2026
PaymentsStripeEU/USDPA, SCCs2026
Model inferenceModel provider (per configured key)EU or US depending on providerDPA, SCCs where applicable; bring-your-own key available2026
Web searchSearch providers (per configured key)VariesDPA where available; query text only2026
AnalyticsSelf-hosted, cookielessEUNo third party2026

Changes are announced 30 days ahead by email to workspace owners.

Data processing agreement

Every plan includes a DPA under Art. 28 GDPR, accepted at signup and downloadable from Settings. Enterprise customers may sign a countersigned copy.

Annexes

  • Subject matter, nature and purpose of processing
  • Types of personal data and categories of data subjects
  • Technical and organisational measures
  • Approved subprocessors
Read the DPA

AI Act Art. 50

  • Output is marked AI-generated until you approve it
  • Approval is logged with the approver and the time
  • Reports carry a disclosure
  • Person research is limited to professional roles
  • Private-life data is out of scope by system rule

Tenant isolation

Row-level security in the database, not application filters. Every query runs inside the tenant's row-level policy, so a bug in application code cannot reach another tenant's rows.

Agent sandbox

Agents and the Ops Console run in an isolated container with no route to the database, no shell, and outbound access only through an allowlist proxy. Tenant MCP tools extend what an agent can reach without extending the blast radius.

Secrets

Provider keys and MCP credentials are encrypted at rest and never returned by the API. A test probe confirms a connection without exposing the credential.

Incidents and enquiries

Report a security issue to start@teleroids.io. We acknowledge reports within two business days. Data-protection enquiries go to the address in the imprint.

start@teleroids.io

This page describes the platform as built. It is not legal advice.

See Caicle on the accounts you actually sell to

Start a free trial in minutes, or send us three domains and we will run them live with you.