Dinobridge — Home ENDE

Security

Security and confidentiality.

Dinobridge is one senior AI expert who gets given access to other people’s contracts, patient records, case files and research data. This page is the full answer to what happens to them, written before you asked.

If something you need is not here, write to us. We answer security questions in writing within two working days, we will complete your questionnaire, and we will mark anything we cannot answer as “no” rather than as “in progress”.

Our approach, in three rules.

  1. Your data stays in your systems.

    Everything we build runs in your own tenancy, under your own accounts, with your own API keys billed directly to you. We are not a hosting provider and we do not want to be one. We hold no credential you cannot revoke in an afternoon.

  2. Confidentiality is designed first, not added later.

    For regulated work — patient files, case documents, children’s data, research under ethics approval — the constraints get written down before anything is designed. Some workflows do not survive that. Those do not get built, and we say so rather than working around it.

  3. Everything is recorded.

    Who did what, on which document, when, and whether a person accepted or rejected it. A system nobody can audit is not deployable, whatever else it can do. This is the first thing we design, not the last.

What we sign before we see anything of yours.

  • A mutual non-disclosure agreement.
  • A data processing agreement under Art. 28 DSGVO.
  • A one-page scope naming exactly which systems we get access to, and for how long. Access is granted by you and revoked by you at the end of each phase; we hold no standing administrator access.
  • For law firms, a separate confidentiality undertaking in Textform under §43e BRAO, in which we are expressly instructed as to the criminal consequences of a breach under §203 StGB, and which states whether any further person may be involved.

Where processing happens.

  • Client systems run in your own tenancy, in the region you choose.
  • Where a document has to be sent to a model to be read, the provider, the region and the terms are named in the proposal and in the data processing agreement, so you can put them to your own data protection officer before anything is signed. No processing outside the EU. If a workflow would require it, you hear that before it is designed — §43e BRAO requires comparable protection for services performed abroad, and the simplest way to satisfy that is not to go abroad.
  • No training on your content, and no retention by a provider beyond the request.
  • Names and identifiers are removed wherever data has to leave your systems at all.

Human oversight.

No decision, diagnosis, valuation, grade, verdict or signature is ever produced by a system we build. No output reaches a client, a counterparty or a patient without a person accepting it. There is no accept-all button in anything we have built; we were asked for one and refused. Every extracted fact is pinned to the page and paragraph it came from, so checking it takes seconds, and the system returns the exact text of a norm or a clause rather than paraphrasing it.

Access control.

Systems act as the signed-in user, so an AI action inherits exactly the permissions that person already has and never more. If someone cannot open a matter today, nothing we build lets them open it tomorrow. Our own access is named in the scope document, limited to the work, granted by you and revoked by you.

AI governance.

Every engagement produces a written AI use policy for your business: what AI may and may not do here, who decides, what is logged, and which tools are approved or refused. Under Article 4 of the EU AI Act, organisations that use AI at work must support AI literacy among the staff who use it, and national authorities have had supervisory powers since 2 August 2026. This document, and the workshop that goes with it, are how we help you meet that. It is not legal advice, and we would rather you had your own adviser confirm it.

Documentation, exit and portability.

A written handover for every system, produced the week it is built: what runs where, which service does what, how to change a rule, how to switch it off, what breaks if you do, and what to look for when something looks wrong. Written for the named owner on your team and tested by having them use it while we watch. On exit: the code is already in your repository, the credentials are already yours, the data is already in your systems, and on request you get a full export of the logs and written confirmation that we hold nothing of yours. Nothing needs a licence, account, server or subscription of ours.

This website itself.

Static pages, no cookies, no analytics, no usage profiles, no application server. The site is hosted on GitHub Pages (GitHub, Inc., US) behind Cloudflare (Cloudflare, Inc., US); the contact form runs through Formspree (US) and the booking calendar through Cal.com (US), which loads only when you click it. All four are set out in the Datenschutzerklärung. They handle enquiries, not client work — no client material of any kind passes through them, and none of them appears in a client engagement.

Datenschutz ↗

What we do not have.

We are not certified to ISO 27001, SOC 2 or TISAX. We do not run a security team, a 24/7 monitoring service or a penetration-testing programme. We are one senior engineer with a written way of working, no employees and no subcontractors. If your procurement requires certification or an insurance certificate, we are not the right supplier and you will hear that on the first call rather than in week six.

Security questions.

Write to us and we answer in writing within two working days. Send your questionnaire and we will complete it — marking anything we cannot answer as “no” rather than as “in progress”.