Codi is designed for regulated environments. All data is stored and processed within the EU, with tenant isolation, role-based access, and full audit logging.
All customer materials, analysis results, and metadata are stored and processed exclusively within EU hosting regions. Data does not leave the EU.
This is a hard architectural constraint, not a policy statement.
Enterprise deployments operate in isolated environments. No infrastructure or data is shared between clients.
Each tenant's documents, analyses, and workspace data remain logically and physically separated from all other tenants.
Customer documents and analysis results are never used to train or improve centralised models or third-party AI systems.
We configure model provider APIs with zero-retention and no-training settings where available.
Customers control the materials and analysis results in their workspace. Job bags, findings, and audit logs persist until deleted by the customer or per agreed retention policy.
Contact us to discuss retention requirements specific to your organisation.
Role-based access controls ensure that only authorised users can view or edit job bags and findings.
All events — uploads, analysis runs, user activity, results — are logged with timestamps and user attribution for full auditability.
We're happy to provide architecture documentation, security questionnaires, or a technical discussion to support your due diligence process.