Trust Center

How we handleyour data.

We are an early stage company handling sensitive financial documents. Here is an honest picture of how we protect your data today, and where we are still maturing.

GDPR
EU AI Act
LOPDGDD

Our Approach to Security

G2-F is built on AWS, hosted entirely in the EU (Frankfurt, eu-central-1). We run on managed Kubernetes (EKS) and keep our environments separate: development, staging, and production. We do not yet hold formal certifications such as SOC 2 or ISO 27001. We follow widely accepted security practices and are working toward formal attestation as we grow.

Access to production systems follows least privilege and is limited to a small number of engineers. Authentication is handled through a single sign on flow with sessions scoped to our domain, and passwords are stored hashed (bcrypt). We continuously evaluate the third party providers and subprocessors we rely on before integrating them.

Infrastructure and Encryption

All traffic to and within our platform is encrypted in transit using TLS. Data at rest, including documents and databases, is encrypted using our cloud provider’s managed encryption. Documents are uploaded directly to object storage (S3) and processed within our EU infrastructure.

Our core subprocessors are Amazon Web Services (hosting, storage, EU region) and Microsoft Azure OpenAI (field extraction). We deploy changes through an automated, version controlled pipeline, so deployments are repeatable and auditable.

How Jeff Uses AI

Jeff, our AI agent, classifies, extracts, matches, and reconciles financial documents. Document understanding runs on our own GPU models for OCR and parsing, and field extraction uses Azure OpenAI. Your data is never used to train or fine tune any model, neither ours nor our providers’. Azure OpenAI processes prompts without retaining them for training.

Each user session is logically isolated, with its own working data and server side separation. Jeff operates within the conversation only: it has no shell or code execution access. Its outputs are designed to support professional judgment, not replace it. Human review remains an essential part of every audit workflow.

Regulatory Compliance

G2-F acts as a data processor under the GDPR and processes personal data only on your documented instructions, for the purpose of delivering the service. We practice data minimization, offer a Data Processing Agreement (DPA) to every customer, and support data subject rights. If a personal data breach occurs, we will notify affected customers without undue delay.

Because Jeff assists with financial verification but does not decide it autonomously, we keep human oversight over AI outputs at all times, consistent with the principles of the EU AI Act. We are transparent about what the system can and cannot do.

Data Protection

Personal data is processed only for the purposes you instruct, and retained only as long as needed to provide the service. Uploaded documents and their derived data can be deleted on request.

We are a small, focused team, and data protection responsibilities are clearly owned internally. As we grow we are formalizing our policies, monitoring, and incident response procedures. We would rather tell you honestly where we are than overstate our maturity.

Documentation

Our Data Processing Agreement is available on this site. Additional documentation, such as the subprocessor list, data flow overview, and security details, is available on request or under NDA.

Questions about security?

For security, privacy, or compliance-related questions, please get in touch.

team@g2-f.com

Let Jeff carrythe heavy work.