Your data is the whole point

You are handing us your supplier list, your site data and your cost structure. This page tells you how we protect it, what we do with it, and what we do not.

Request security documentation→

Straight answers about AI

No

Do you train AI models on our data?

Sustain uses your data to answer your questions and nothing else. We train, fine-tune or improve no model on customer data, ours or anyone else's.

No

Does AI produce the financial figures?

No. Reasoning, simulation and ranking are deterministic code. Turn the language model off and each number stays identical, which a test enforces on each release. Sustain uses AI only to read documents and to write the explanation around figures it has already calculated.

No

Can another customer's data influence our results?

No. Your knowledge graph, documents and history are yours alone. Sustain ships cross-customer pattern learning switched off. Turning it on would require your opt-in, anonymisation across multiple companies, and human approval.

In two places

Does our data ever leave your infrastructure?

Yes, in two narrow places, both named in the product. In Ask, Sustain sends your question and the matching passages from your own documents to Mistral, our AI sub-processor, which composes the answer. Reading a document the deterministic parser cannot interpret can use the same model. The rest runs inside Sustain: the graph, the reasoning, the simulation and the ranking stay here, and no external model produces a figure.

Yes

Is there human oversight?

Yes. Sustain analysts govern the rules, thresholds and assumptions, with changes reviewed, tested against a fixed benchmark and audited before release. And Sustain does not make your decision. It produces the analysis; your management decides.

Architecture

Two separate systems, by design

The product you use and the internal system our staff use run as separate services, on separate databases, under separate credentials. The customer product cannot read another customer's data. Its structure rules that out, rather than a check that someone could misconfigure.

Customer plane · public

The product you use

  • Your documents
  • Your knowledge graph
  • Your recommendations
  • Your history

Single-tenant by construction. Your identity determines your data at the database level.

Billing window
Reference data

Control plane · internal only

The console we use

  • Employee accounts
  • Subscriptions
  • Analyst review
  • Regulatory corpus

It has no public internet address. Only named Sustain staff reach it, and we log each access.

The two meet only through narrow, read-only, customer-scoped windows

Your dataAnswering your questionsModel training

We do not use anything you upload to train or fine-tune a model, ours or a third party's.

Tenant isolation

Our most important control

We enforce isolation at five independent layers, from the identity token down to object storage. Each holds on its own, so defeating one still reaches no other customer's data.

Your data

Your identity

Sustain reads your customer identity from the verified session token and nowhere else. It ignores any identity in a request body, a header, or a URL, so the browser cannot substitute one.

  • Sustain takes customer identity from a verified session, and ignores anything the browser sends
  • Row-level security enforced in the database itself, not only in application code
  • Separate knowledge graph namespace and storage prefix per customer
  • An automated test suite attempts cross-customer access on each release and must fail each attempt

Data protection

At rest and in transit

  • TLS 1.3 in transit, including between our own internal services
  • Encryption at rest for databases, object storage and backups
  • Uploaded documents in private storage, reachable only through short-lived signed links after an ownership check
  • Uploads validated by file signature, size-capped, malware-scanned and parsed in an isolated environment with no internet access

Access control

Yours and ours

AuthenticationManaged identity provider. Sustain stores no password.
Multi-factorAvailable for all users, enforceable across your organisation. Mandatory for all Sustain staff.
Single sign-onSAML and OIDC.
RolesAdministrator and member. Administrators manage their own organisation only.
SessionsIdle and absolute timeouts, revocation on password or MFA change, sign out everywhere.
Staff accessLeast privilege by capability. Any access to customer data is audit logged.
SCIM provisioningOn the roadmap.

Infrastructure

The infrastructure

Sustain runs on managed infrastructure with network segmentation between tiers. Databases and internal services hold no public endpoint and are reachable only over a private network. The edge provides DDoS protection, a web application firewall and rate limiting.

  • No database is reachable from the public internet
  • Least-privilege credentials per service; no shared administrator accounts
  • Dependency, secret, container and infrastructure scanning on each build
  • Signed, verified artifacts to production

Data residency

EU by default

Sustain stores and processes all customer data in the European Union: databases, knowledge graphs, uploaded documents and backups. Sustain is a Danish company. The Data Processing Agreement names our subprocessors, and we notify customers before adding one.

Privacy and GDPR

We are your processor

For the data you upload, you are the controller and Sustain is the processor. We sign a Data Processing Agreement with each customer covering processing on documented instructions, security measures, subprocessor rules, assistance with data subject requests and breach notification, and deletion at the end of the contract.

  • Data Processing Agreement available before contract signature
  • Subprocessors named in the DPA, with advance change notification
  • Support for access, correction, deletion and portability requests
  • Breach notification without undue delay and within statutory deadlines

Retention and deletion

The meaning of delete

Delete your data or end your contract, and the deletion propagates across each store: the database, the knowledge graph, the search index, uploaded files, caches and backups, on a documented schedule. An automated audit then verifies that nothing remains orphaned. We keep the records the law requires us to keep, such as invoices and contract acceptance, and we document the basis.

Compliance status

Our current position

We will not display a certification badge we have not earned. Here is the honest position.

ItemStatus
GDPRIn place. DPA available.
EU AI Act, Article 50 transparencyIn place.
EU data residencyIn place.
Penetration testPlanned before general availability.
SOC 2 Type IIRoadmap, 2027.
ISO 27001Roadmap.

We complete security questionnaires and will walk your team through our controls in detail.

Incident response

Detection through to notification

We monitor for authentication anomalies, authorisation failures, unusual export volume and any attempted cross-customer access, which should not occur and so raises an alert at once. Documented runbooks cover containment, assessment, notification and remediation, with named owners.

Business continuity

Backups and recovery

  • Automated encrypted backups, held apart from production
  • Restores tested on a schedule, not assumed to work
  • Recovery point objective and recovery time objective documented and shared under NDA

Contact

Talk to us

For security documentation, questionnaires or a review call, contact security@trysustain.app. To report a vulnerability, use the same address. We will acknowledge within one business day and we do not take legal action against good-faith researchers.

Turn compliance into competitive advantage.

See your own data become a ranked set of decisions.

One price per company size. Everything included.