You are handing us your supplier list, your site data and your cost structure. This page tells you how we protect it, what we do with it, and what we do not.
Do you train AI models on our data?
Sustain uses your data to answer your questions and nothing else. We train, fine-tune or improve no model on customer data, ours or anyone else's.
Does AI produce the financial figures?
No. Reasoning, simulation and ranking are deterministic code. Turn the language model off and each number stays identical, which a test enforces on each release. Sustain uses AI only to read documents and to write the explanation around figures it has already calculated.
Can another customer's data influence our results?
No. Your knowledge graph, documents and history are yours alone. Sustain ships cross-customer pattern learning switched off. Turning it on would require your opt-in, anonymisation across multiple companies, and human approval.
Does our data ever leave your infrastructure?
Yes, in two narrow places, both named in the product. In Ask, Sustain sends your question and the matching passages from your own documents to Mistral, our AI sub-processor, which composes the answer. Reading a document the deterministic parser cannot interpret can use the same model. The rest runs inside Sustain: the graph, the reasoning, the simulation and the ranking stay here, and no external model produces a figure.
Is there human oversight?
Yes. Sustain analysts govern the rules, thresholds and assumptions, with changes reviewed, tested against a fixed benchmark and audited before release. And Sustain does not make your decision. It produces the analysis; your management decides.
Two separate systems, by design
The product you use and the internal system our staff use run as separate services, on separate databases, under separate credentials. The customer product cannot read another customer's data. Its structure rules that out, rather than a check that someone could misconfigure.
Customer plane · public
Single-tenant by construction. Your identity determines your data at the database level.
Control plane · internal only
It has no public internet address. Only named Sustain staff reach it, and we log each access.
The two meet only through narrow, read-only, customer-scoped windows
We do not use anything you upload to train or fine-tune a model, ours or a third party's.
Our most important control
We enforce isolation at five independent layers, from the identity token down to object storage. Each holds on its own, so defeating one still reaches no other customer's data.
Your identity
Sustain reads your customer identity from the verified session token and nowhere else. It ignores any identity in a request body, a header, or a URL, so the browser cannot substitute one.
At rest and in transit
Yours and ours
| Authentication | Managed identity provider. Sustain stores no password. |
| Multi-factor | Available for all users, enforceable across your organisation. Mandatory for all Sustain staff. |
| Single sign-on | SAML and OIDC. |
| Roles | Administrator and member. Administrators manage their own organisation only. |
| Sessions | Idle and absolute timeouts, revocation on password or MFA change, sign out everywhere. |
| Staff access | Least privilege by capability. Any access to customer data is audit logged. |
| SCIM provisioning | On the roadmap. |
The infrastructure
Sustain runs on managed infrastructure with network segmentation between tiers. Databases and internal services hold no public endpoint and are reachable only over a private network. The edge provides DDoS protection, a web application firewall and rate limiting.
EU by default
Sustain stores and processes all customer data in the European Union: databases, knowledge graphs, uploaded documents and backups. Sustain is a Danish company. The Data Processing Agreement names our subprocessors, and we notify customers before adding one.
We are your processor
For the data you upload, you are the controller and Sustain is the processor. We sign a Data Processing Agreement with each customer covering processing on documented instructions, security measures, subprocessor rules, assistance with data subject requests and breach notification, and deletion at the end of the contract.
The meaning of delete
Delete your data or end your contract, and the deletion propagates across each store: the database, the knowledge graph, the search index, uploaded files, caches and backups, on a documented schedule. An automated audit then verifies that nothing remains orphaned. We keep the records the law requires us to keep, such as invoices and contract acceptance, and we document the basis.
Our current position
We will not display a certification badge we have not earned. Here is the honest position.
| Item | Status |
|---|---|
| GDPR | In place. DPA available. |
| EU AI Act, Article 50 transparency | In place. |
| EU data residency | In place. |
| Penetration test | Planned before general availability. |
| SOC 2 Type II | Roadmap, 2027. |
| ISO 27001 | Roadmap. |
We complete security questionnaires and will walk your team through our controls in detail.
Detection through to notification
We monitor for authentication anomalies, authorisation failures, unusual export volume and any attempted cross-customer access, which should not occur and so raises an alert at once. Documented runbooks cover containment, assessment, notification and remediation, with named owners.
Backups and recovery
Talk to us
For security documentation, questionnaires or a review call, contact security@trysustain.app. To report a vulnerability, use the same address. We will acknowledge within one business day and we do not take legal action against good-faith researchers.
See your own data become a ranked set of decisions.
One price per company size. Everything included.