Trust
Trust you can verify
graal runs on your infrastructure, with your identities and under your rules. Everything that happens there can be reviewed, and nothing leaves without you. This page gathers what your security, compliance and data protection teams will check.
The model
You operate. graal installs without privileges. Nothing leaves.
graal is software you install: it holds neither your data nor your identities, and it requires no administration rights on your cluster.
Every action, whether it comes from a person or from an AI agent, goes through the same per-project permissions and leaves a record in the audit trail.
Responsibilities
Who does what
How responsibilities are split between the vendor, your organization and, if you choose one, your hosting provider.
| Area | graal (vendor) | You | Your hosting provider |
|---|---|---|---|
| Software and patches | Publishes releases, security fixes and their notes | Plans and applies upgrades | — |
| Physical infrastructure | — | Your datacenter, if you host it yourself | Datacenters and hardware; depending on the offer, SecNumCloud qualification or HDS certification |
| Cluster and network | Runs without cluster administration rights | Operates the cluster, quotas and network | Provides and maintains the Kubernetes offer, where applicable |
| Identities and permissions | Provides SSO, per-project roles and service accounts | Manages the directory, roles and authorized agents | — |
| Data | Does not access it, except for interventions you authorize | Owns it, classifies it and decides how it is used | Hosts it physically |
| Audit | Logs every action, human or agent | Retains and uses the logs | — |
| Vulnerabilities | Handles reports and publishes fixes | Applies fixes and reports your incidents | As per its contract |
Guarantees
Six design guarantees
Isolation and privileges
Restricted pods (PSA restricted), no rights on the cluster, no custom resources, one network policy per workload.
See securityIdentity
OIDC and SAML SSO, LDAP or Active Directory, permissions per project and per resource.
AI agents
One service account per project, human approval for sensitive actions, instant revocation.
See AI agentsSecrets
Encrypted at rest (AES-GCM), referenced by name, never displayed or written into code.
Nothing leaves
No telemetry, no third-party service: no SaaS, no external fonts, no external captcha.
See sovereigntySoftware supply chain
Images pinned by digest and signed, software bill of materials (SBOM) shipped with every release.
Qualified hosting
The label belongs to the hosting provider
SecNumCloud qualifies cloud offers, and HDS certification applies to health data hosting providers. graal deploys with a SecNumCloud-qualified or HDS-certified hosting provider, just as it does in your own datacenter.
The provider then holds the label for its offer; graal brings a platform that installs without privileges and sends nothing outside.
Go further
The details, topic by topic
Compliance
NIS2, DORA, Data Act, AI Act, SREN: what graal helps you trace and document.
See complianceDocuments
Documents on request
Architecture pack, detailed responsibility matrix, answers to your security questionnaires: we send them to you directly, with no third-party portal and no account to create.
Get the security pack
Architecture pack, detailed responsibility matrix and answers to your questionnaires: on request, directly, with no third-party portal.