← About

Trust & Security

The facts a security or procurement review needs first, stated precisely. Everything on this page is verified; where something usual for a page like this is not yet published, it says so rather than approximating.

Certification

ISO/IEC 27001:2022
Certified. Transition from the 2013 standard announced 21 August 2025.
ISO/IEC 27001:2013
First certified May 2022 (announced 20 May 2022); superseded by the 2022 transition above.

Entity and footprint

Legal entity
Windmill Smart Solutions AG
Headquarters
Switzerland
Offices
Europe, the United States and India

How client data and AI systems are handled in delivery

Controls are defined in proportion to the product and engagement. These are the ones that apply to every AI system Windmill builds or operates. How they become product and engineering work is described in Evaluation & Assurance and on the Approach page.

No training on client data
Work runs under enterprise API terms and zero-retention agreements. Client documents, customer data and embeddings are not used to train foundation models.
Data residency
Client sandbox and production data can be hosted exclusively in Swiss and EU regions, for example Azure Switzerland North or Hetzner Falkenstein, or in the client’s own cloud.
Private endpoint isolation
Agents reach databases and model inference endpoints through private endpoints with no public IP exposure.
Role-based access control
Tenant segregation, least-privilege API tokens and session auditing.
Immutable audit logs
Reasoning chains, tool executions and user overrides are captured in tamper-evident logs.
Release gates on AI behaviour
Audra Eval runs regression tests on answer fidelity, citations and hallucination rate; a prompt change or model upgrade that fails the agreed thresholds does not deploy.
Human oversight
Autonomy is graduated. High-stakes actions require human sign-off through explicit escalation workflows with confidence telemetry.

A starting point for your review

Share the public security overview with your reviewers. It brings the published facts together and lists the documents and project-specific answers to request before starting.

The overview is not a certificate. Request the current certificate, its scope and validity dates for your due diligence.

Not yet published here

  • - The sub-processor list.
  • - The current certificate and detailed assurance documents.
  • - A named individual for security questionnaires.

Until then, security questionnaires and due-diligence requests go to security@windmill.digital and are routed to the accountable person.