In Martes AI projects, sensitive data enters late and never by accident. Training runs on Claude Team with no confidential documents uploaded, and by default that environment does not train models on your organisation's content. The Company Brain is built on AWS or Cloudflare inside European territory, in the client's tenant and with the client's keys: if the relationship ends, the system keeps running, because it is an asset of the client company. Governance and privacy notices are handled by a partner law firm.
Frequently asked questions on security and data handling
Does my company data leave Europe?
At rest, no: the Company Brain runs on infrastructure inside European territory, on AWS or Azure, and the data stays in the client company’s tenant. When an answer is needed, the pieces it requires go through the AI model the client chose, with the client’s keys: if that step must stay in Europe too, we use the models offered by AWS or Azure on European servers. In the first phase, the training, sensitive data never enters the perimeter: we work on Claude Team without uploading it.
Who holds the keys to the Company Brain?
The client company. The Company Brain is configured on the client’s tenant with the client’s keys, and Martes AI does not access the data. The software belongs to Martes AI under a licence; the content of the brain belongs to the client, in open formats and exportable.
Is company content used to train AI models?
No. Claude Team, the environment used during the training, does not train models on your organisation’s content: that is the default setting of the plan, not something you have to switch on.
How do you handle the AI Act and the GDPR?
Governance and privacy notices are handled by a partner law firm, the same one that drafts the general terms of contract for Martes AI. In the assessment call we define in writing which data will be processed, where it lives and on what legal basis, before anything is signed.
Our management system is old and the APIs are unusable. How do you handle that?
We work with your IT team to pick the workable route together: read-only database access when the APIs cannot carry the load, or the API documentation when it is usable. No write permissions are needed to start. TeamSystem, Zucchetti and PEC are the normal context, not an edge case.
Do we end up tied to Martes AI or to a single AI provider?
No. The platform is model independent: the second brain is a folder of files and works with different engines. If a better provider comes along, the work already done does not have to be redone.
Can the team do damage with AI?
In the first phase sensitive documents never enter the perimeter. The level of data goes up in the second phase, when the infrastructure is configured and logged. With Claude Team the company gets SSO and admin controls over connectors, which remove the use of unauthorised tools.