Security & Governance

ISO 27001:2022

Swiss HQ. ISO 27001:2022. Evals in Production.

Designed for the Chief Information Security Officers, Compliance Directors, and Risk Committees of Tier-1 banks and health networks. We design and operate AI systems that can stand up to formal regulatory audit.

Certification

ISO 27001:2022 Certified

Independently audited and certified information security management system. Covers product engineering, cloud infrastructure, employee access controls, and incident response protocols.

Jurisdiction

Swiss Headquarters & Data Sovereignty

Windmill Smart Solutions AG is incorporated in Baar / Zug, Switzerland. All client sandbox and production data can be hosted exclusively in Swiss and EU data regions (e.g. Azure Switzerland North / Hetzner Falkenstein).

Model Governance

Zero Training on Client Data

We operate under strict enterprise API terms and isolated zero-retention agreements. Your proprietary documents, customer PII, and vector embeddings are never used to train foundation models.

Quality Gates

Audra Eval Automated CI/CD Gates

Continuous regression testing on answer fidelity, citations, and hallucination rates. Any prompt adjustment or model version upgrade must pass automated thresholds before deployment.

UX Safety

Human-on-the-Loop Governance

Autonomy is a graduated scale, not an all-or-nothing leap. We design deterministic escalation workflows where high-stakes actions require human sign-off with clear confidence telemetry.

Procurement

Multi-Year SLA & Audit Evidence Packs

Our 24-60 month Run partnerships include comprehensive annual audit evidence packs, penetration testing summaries, and vendor risk reviews for your internal InfoSec and Compliance teams.

Architecture Blueprint

How we isolate client AI infrastructure

Whether deploying in your dedicated virtual private cloud (VPC) or our ISO-certified infrastructure, every tier of the AI Delivery Pipeline enforces strict privilege separation, cryptographic hashing of audit trails, and deterministic prompt validation.

  1. Virtual Private Endpoint Isolation: AI agents access databases and LLM inference endpoints through private endpoints with no public IP exposure.
  2. Role-Based Access Control (RBAC): Multi-tenant segregation with least-privilege API tokens and continuous session auditing.
  3. Immutable Audit Logs: Every reasoning chain, tool execution, and user override is captured in tamper-evident logs for auditability.

Send this page directly to your InfoSec team

Need our ISO certificate, SOC 2 alignment mapping, or Data Protection Agreement (DPA)? Contact our security team for immediate turnaround.