Forgeron3
Security & GDPR·Four written, verifiable commitments

Your data stays
yours.

French hosting, watertight perimeter per assistant, no training on your documents, contractual reversibility. No gray areas.

Four commitments

Sovereign.
Watertight.
Reversible.

/ 01 — Sovereignty

Hosted in France.

Hosted in France (Strasbourg and Gravelines datacenters). No client data leaves the country, including backups and logs.

Encryption at rest and in transit (TLS 1.3, AES-256). Keys managed in France, never held by a non-European third party.

  • DatacentersFrance (Strasbourg, Gravelines)
  • ComplianceGDPR by design
  • EncryptionTLS 1.3 · AES-256
  • Cloud ActOut of scope
/ 02 — GDPR

Article 28 subprocessor.

DPA (data processing agreement) signed systematically before service starts. Processing register available on request.

DPO reachable directly (dpo@forgeron3.fr), reply within 24 business hours.

  • DPASigned before go-live
  • RegisterAvailable to clients
  • DPOReachable directly
/ 03 — Isolation

No training.

Your documents never feed a model, neither ours nor a third party's. It's both a contractual and a technical commitment: each assistant's perimeter is isolated, continuously monitored and logged.

European sovereign models for the Sovereign and Public profiles. Closed models (Mistral, OpenAI Europe) on the other profiles, never self-hosted.

  • TrainingNever on your data
  • ModelsEU-only or Mistral/OpenAI EU
  • AuditFull log, exportable
  • PerimeterWatertight per assistant
/ 04 — Reversibility

You take back everything.

At any time you can request a full export: documents, conversations, logs, configuration. Delivered within 7 days in open formats (JSON + PDF). Full deletion of your entire perimeter within 30 days, with a written attestation.

No commitment, 30-day termination. No exit fees.

  • Export time≤ 7 days
  • FormatsJSON · PDF · CSV
  • Deletion≤ 30 days, attested
  • Exit fees€0
A question from your CIO, CISO or DPO?

We reply in writing,
within 24 business hours.