Trust

Trust you can verify

graal runs on your infrastructure, with your identities and under your rules. Everything that happens there can be reviewed, and nothing leaves without you. This page gathers what your security, compliance and data protection teams will check.

The model

You operate. graal installs without privileges. Nothing leaves.

graal is software you install: it holds neither your data nor your identities, and it requires no administration rights on your cluster.

Every action, whether it comes from a person or from an AI agent, goes through the same per-project permissions and leaves a record in the audit trail.

Responsibilities

Who does what

How responsibilities are split between the vendor, your organization and, if you choose one, your hosting provider.

Areagraal (vendor)YouYour hosting provider
Software and patchesPublishes releases, security fixes and their notesPlans and applies upgrades—
Physical infrastructure—Your datacenter, if you host it yourselfDatacenters and hardware; depending on the offer, SecNumCloud qualification or HDS certification
Cluster and networkRuns without cluster administration rightsOperates the cluster, quotas and networkProvides and maintains the Kubernetes offer, where applicable
Identities and permissionsProvides SSO, per-project roles and service accountsManages the directory, roles and authorized agents—
DataDoes not access it, except for interventions you authorizeOwns it, classifies it and decides how it is usedHosts it physically
AuditLogs every action, human or agentRetains and uses the logs—
VulnerabilitiesHandles reports and publishes fixesApplies fixes and reports your incidentsAs per its contract

Guarantees

Six design guarantees

Isolation and privileges

Restricted pods (PSA restricted), no rights on the cluster, no custom resources, one network policy per workload.

See security

Identity

OIDC and SAML SSO, LDAP or Active Directory, permissions per project and per resource.

AI agents

One service account per project, human approval for sensitive actions, instant revocation.

See AI agents

Secrets

Encrypted at rest (AES-GCM), referenced by name, never displayed or written into code.

Nothing leaves

No telemetry, no third-party service: no SaaS, no external fonts, no external captcha.

See sovereignty

Software supply chain

Images pinned by digest and signed, software bill of materials (SBOM) shipped with every release.

Qualified hosting

The label belongs to the hosting provider

SecNumCloud qualifies cloud offers, and HDS certification applies to health data hosting providers. graal deploys with a SecNumCloud-qualified or HDS-certified hosting provider, just as it does in your own datacenter.

The provider then holds the label for its offer; graal brings a platform that installs without privileges and sends nothing outside.

Go further

The details, topic by topic

Security

Isolation, identity, agents, secrets, audit and software supply chain.

See security

Sovereignty

What “sovereign” means here, and why the question matters now.

See sovereignty

Compliance

NIS2, DORA, Data Act, AI Act, SREN: what graal helps you trace and document.

See compliance

Disclosure

Report a vulnerability in good faith, and follow its fix.

See the policy

Documents

Documents on request

Architecture pack, detailed responsibility matrix, answers to your security questionnaires: we send them to you directly, with no third-party portal and no account to create.

Get the security pack

Architecture pack, detailed responsibility matrix and answers to your questionnaires: on request, directly, with no third-party portal.