Privacy & Trust
Privacy and security by design.
ALETTA's technology strategy prioritizes the protection of personal information and the responsible development of artificial intelligence.
01
Private AI
Our strategy emphasizes controlled AI infrastructure and private processing where appropriate, with reduced dependence on external AI providers. We do not claim that every model or processing operation runs on our own infrastructure.
02
Information security
Access control, encryption, secure development practices and information governance are core principles of the platform's design. Controls still in preparation are described as planned, not implemented.
03
Personal privacy
Transparency, data minimization and meaningful user control. Some lifestyle and wellbeing information may constitute health data under applicable data-protection law, and is treated accordingly.
04
Responsible AI
Model evaluation, clearly defined intended uses, human oversight and appropriate safeguards, with AI supporting rather than replacing individual decision-making.
Certification & regulatory roadmap
Prepared for the European market.
ALETTA is preparing its security and compliance framework for the European market. The target is to complete the applicable pre-launch security and compliance work before the end of 2026.
- ISO/IEC 27001 certification preparationIn progress
- GDPR compliance workIn progress
- AI governance and applicable EU AI Act obligationsIn progress
- Privacy and security assessmentsIn progress
- Application security testingIn progress
- Further standards determined by the final product's scope and legal requirementsIn progress
ISO/IEC 27701 and NEN 7510 may be assessed if relevant to the final operating model; not every standard is mandatory for a European lifestyle application. All certifications are shown as pending until independently achieved, and internal policy work is not equivalent to accredited certification. No absolute guarantee of security or privacy can be given.
