Trust Center
Who processes data on our behalf, where, under which agreements, and what each of them can document.
- Trustbox ApS is the data controller
- Valiss AI is operated by Trustbox ApS, CVR 37588822, Lyngbyvej 83 A, 2100 Copenhagen. Questions go to hello@valiss.co.
- This site is hosted in the EU
- valiss.co runs on Vercel in the Stockholm region. Our own systems and backups are hosted in the EU, and we choose EU regions wherever a provider offers one.
- Transfers rest on SCC or the Data Privacy Framework
- Where a subprocessor sits outside the EEA, the transfer is covered by the European Commission standard contractual clauses or the EU-US Data Privacy Framework.
- A data processing agreement before we start
- When we process personal data for a customer, we sign a data processing agreement first. It lists the subprocessors used in that specific solution.
Subprocessors
Every third party that may process personal data when you use this website, order a Signal audit, or run a solution we have built. A customer solution uses only the ones it needs.
22 subprocessors
AI models
-
Language models for conversations, drafting and analysis in customer solutions, and ChatGPT queries in Signal audits.
Signal auditsCustomer solutionsUnited StatesOpenAI OpCo, LLCEU entity: OpenAI Ireland Ltd.Transfer basis: standard contractual clausesSOC 2ISO 27001ISO 27017/18ISO 42001CSA STAR -
Claude models for conversations, drafting and analysis in customer solutions, and Claude queries in Signal audits.
Signal auditsCustomer solutionsUnited StatesAnthropic, PBCEU entity: Anthropic Ireland, LimitedTransfer basis: standard contractual clausesSOC 2ISO 27001ISO 27017/18ISO 42001CSA STAR -
Claude models with data processing in the EU, for customer solutions that require it.
Customer solutionsIreland · EU data regionAnthropic Ireland, LimitedData stays in the EEASOC 2ISO 27001ISO 27017/18ISO 42001CSA STAR -
Gemini models in customer solutions and Gemini queries in Signal audits. Google Places for public business information; no guest or customer data is sent there.
Signal auditsCustomer solutionsUnited States · EU data regionGoogle LLCEU entity: Google Cloud EMEA LimitedTransfer basis: EU-US Data Privacy FrameworkSOC 2ISO 27001ISO 27017/18ISO 42001CSA STARPCI DSSEU-US DPF -
Queried in Signal audits to see how it describes a business. Only public information is sent.
Signal auditsUnited StatesPerplexity AI, Inc.Transfer basis: standard contractual clausesSOC 2ISO 27001 -
European language models in customer solutions, hosted in the EU by default.
Customer solutionsFrance · EU data regionMistral AI SASData stays in the EEASOC 2ISO 27001 -
United StatesSpaceXAI LLCTransfer basis: standard contractual clausesFormerly X.AI Corp.; part of SpaceX since 2026. -
Llama open models, run on hosting listed on this page. Meta is the licensor and receives no data.
Customer solutionsUnited StatesMeta Platforms, Inc.EU entity: Meta Platforms Ireland LimitedNo personal data is sent
Voice and telephony
-
United StatesCartesia AI, Inc.Transfer basis: standard contractual clausesSOC 2PCI DSS -
United States · EU data regionTwilio Inc.EU entity: Twilio Ireland LimitedTransfer basis: EU-US Data Privacy FrameworkSOC 2ISO 27001ISO 27017/18PCI DSSEU-US DPF
Hosting and infrastructure
-
Hosts valiss.co in the Stockholm region and provides cookieless visitor analytics and speed measurement.
This websiteCustomer solutionsUnited States · EU data regionVercel Inc.Transfer basis: EU-US Data Privacy FrameworkSOC 2ISO 27001PCI DSSEU-US DPF -
United States · EU data regionRailway CorporationTransfer basis: standard contractual clauses -
Object storage for backups of customer solutions, in buckets restricted to the EU jurisdiction.
Customer solutionsUnited States · EU data regionCloudflare, Inc.Transfer basis: EU-US Data Privacy FrameworkSOC 2ISO 27001ISO 27017/18PCI DSSEU-US DPF -
Web hosting for customer websites and small services in EU data centres.
Customer solutionsLithuania · EU data regionHostinger International Ltd.Data stays in the EEAISO 27001PCI DSS -
Azure and Microsoft 365 when a customer solution runs in or connects to the customer’s own Microsoft environment. EU Data Boundary.
Customer solutionsUnited States · EU data regionMicrosoft CorporationEU entity: Microsoft Ireland Operations LimitedTransfer basis: EU-US Data Privacy FrameworkSOC 2ISO 27001ISO 27017/18ISO 42001CSA STARPCI DSSEU-US DPF -
Source code and deployment of the software we build. Personal data is not stored in repositories.
Customer solutionsUnited StatesGitHub, Inc.Transfer basis: EU-US Data Privacy FrameworkSOC 2ISO 27001CSA STARPCI DSSEU-US DPF
Communication and operations
-
Sends our newsletter and service messages, and email from customer solutions.
This websiteCustomer solutionsUnited StatesTwilio Inc.EU entity: Twilio Ireland LimitedTransfer basis: EU-US Data Privacy FrameworkSOC 2ISO 27001ISO 27017/18EU-US DPF -
Content system behind the Journal on valiss.co and content on customer websites. Content is stored in Belgium.
This websiteCustomer solutionsUnited States · EU data regionSanity US Inc.EU entity: Sanity ASData stays in the EEA -
Message channel for notifications and simple bots in customer solutions, only where the customer chooses it.
Customer solutionsUnited Arab EmiratesTelegram Messenger Inc.Transfer basis: standard contractual clausesTelegram publishes no data processing agreement. It is used only as a transport channel; the data a bot receives stays in our systems.
Payments
-
Card payment and invoice payment for our own services and for customer solutions.
This websiteCustomer solutionsDenmark · EU data regionQuickpay ApSData stays in the EEA -
United StatesStripe, Inc.EU entity: Stripe Payments Europe, LimitedTransfer basis: EU-US Data Privacy FrameworkPCI DSSSOC 2EU-US DPF
Analytics and marketing
-
SingaporeAhrefs Pte. Ltd.Transfer basis: standard contractual clausesSOC 2ISO 27001 -
Google Analytics 4 and Google Ads on valiss.co, activated only after you accept analytics and advertising cookies.
This websiteUnited StatesGoogle LLCEU entity: Google Ireland LimitedTransfer basis: EU-US Data Privacy FrameworkISO 27001EU-US DPF
No subprocessor matches your search.
Certifications are those each provider states publicly on its own trust or security page at the time of the last update. Links go to the provider’s own documentation, which may change. The privacy notice describes how we process your data as a visitor or customer; this page lists the providers in use today.
What the certifications mean
A certification says that an independent auditor has checked the provider against a published standard. It does not replace a data processing agreement, but it is the best public evidence of how the provider works.
- SOC 2
- SOC 2 Type II
An independent audit of security, availability and confidentiality controls over a period of at least six months, under the American AICPA framework.
- ISO 27001
- ISO/IEC 27001
The international standard for information security management. Certification means an accredited body has audited the provider’s security organisation.
- ISO 27017/18
- ISO/IEC 27017 and 27018
Extensions of ISO 27001 for cloud services. 27017 covers cloud security controls, 27018 covers protection of personal data in the cloud.
- ISO 42001
- ISO/IEC 42001
The first international standard for AI management systems: how an organisation governs the development and use of AI responsibly.
- EU-US DPF
- EU-US Data Privacy Framework
The provider is on the US Department of Commerce list, so personal data can be transferred from the EEA under the European Commission adequacy decision of July 2023.
- PCI DSS
- PCI DSS
The payment card industry standard for handling card data. Level 1 is the strictest tier, required of the largest payment providers.
- CSA STAR
- CSA STAR
The Cloud Security Alliance registry, where cloud providers document their controls against the Cloud Controls Matrix.
How we choose and manage subprocessors
- 01
EU first
Where a provider offers an EU region or EU processing, we use it. This site, our own systems and our backups are in the EU.
- 02
Agreement before data
We sign the provider’s data processing agreement and check its transfer basis before any personal data flows through it.
- 03
Least access
A solution gets access only to the systems and fields it needs, and an AI model only sees what the task requires.
- 04
Notice of changes
When we add or replace a subprocessor, we update this page and the log below. Customers with a data processing agreement are notified as that agreement sets out.
Changes
- 30 Sep 2026 Trust Center published.
Questions we get
Is our data used to train AI models?
Which subprocessors does our solution use?
Can we get a copy of your data processing agreement?
Where is our data stored?
Need the details for your own review?
We send the data processing agreement, the transfer basis and the subprocessor list for your solution, and answer your security questionnaire.