Your data never trains models
Customer data is never used to train models. Not ours, and not our providers'. Your information is processed to complete your work, and for nothing else.
Notarial and professional work combines sensitive personal data, strict accountability and real legal consequence. Third Rule is engineered for that reality: your data is protected, your decisions stay traceable, and your people stay in control.
ISO/IEC 27001:2022
Information security management
SOC 2 Type II
Security, availability and confidentiality
ISO/IEC 42001
AI management systems
GDPR
EU data protection by design
EU AI Act
Transparency and human oversight
KNB AI-weegschaal
Responsible AI framework for the notariaat
Public AI tools send your documents somewhere else. Ours does not. The Data Shield is our own protection layer: it anonymises and encrypts every privacy-sensitive detail locally, before any AI ever reads it, so the intelligence reaches your desk without your clients' identities leaving the building.
Client data never leaves our infrastructure. Everything runs on private Microsoft Azure infrastructure in the EU, not a public cloud, and never a US-hosted one.
Locally, before any analysis, the Data Shield anonymises names, BSN numbers and other personally identifiable information using advanced NLP and RegEx filtering, and encrypts the rest with AES-256.
The AI only ever receives shielded content. It works on structure, rules and logic, never on the identities of your clients.
Shielded data is never used for the training, fine-tuning or benchmarking of any public or private AI model.
Customer data is never used to train models. Not ours, and not our providers'. Your information is processed to complete your work, and for nothing else.
Data is encrypted in transit and at rest, and sensitive information is anonymised where appropriate before it reaches a model.
Built in the Netherlands and hosted on private Microsoft Azure infrastructure in the EU, not a public cloud. GDPR compliant by design, with your data staying on European soil.
Every access, model call and action is logged. Nothing happens in your environment that cannot be traced back, reviewed and explained.
Material actions pause for human sign-off. Digital employees execute the work, while professionals stay responsible for reviewing and validating outcomes.
Our infrastructure and solutions are developed, monitored and continuously improved by Third Rule, with continuous technical monitoring behind our certified processes.
Role-based access and logical separation between customer environments mean only authorised people reach a given workspace. Access rights follow the principle of least privilege.
Your data remains yours. You decide what enters the environment, how long it is retained and when it is removed, and you can request export or deletion at any time.
CLEON is model agnostic by design and selects the right technology per task. That avoids vendor lock-in and reduces dependence on any single Big Tech provider.
Structured workflows and human approval sit around the AI, so results are dependable and every decision remains traceable and accountable.
Running a vendor assessment? We share our ISO/IEC 27001:2022 certificate, data processing agreement and security documentation with customers and prospects on request.
Third Rule B.V., security and compliance enquiries.