Secure in Every Aspect

When it comes to your data, security is about more than just firewalls. It starts with an independent ownership structure and extends to the highest security standards. Galilea delivers on all fronts—with clean technical implementation and a robust infrastructure.

Certifications

DSGVO
GDPR compliant
AI Act
EU AI ACT compliant
ISO 27001
coming soon
ISO 27001 certified
NIS 2
NIS 2 compliant

Security & Data Protection

Our Measures for Your Security

Data protection and security form the operational foundation of Galilea. Our security measures and infrastructure are the result of years of experience in developing AI applications—ensuring security at every stage of data processing.

01

Data & Communication Security

Data is encrypted with TLS 1.3 during transmission and AES-256 at rest. Strict database separation prevents unauthorized access, and no data is used for LLM training.

02

Security Policies & Compliance

Strict access controls via SSO and 2FA ensure secure authentication and compliance with industry standards.

03

Proaktive Sicherheit und Überwachung

Multi-layered, continuous checks and automated code scans detect and prevent vulnerabilities.

04

Datenzugriff nach dem Minimalprinzip

Administrators have no permanent access to your data—temporary access is granted only upon request and automatically revoked after use.

Founder-Owned, Not Investor-Driven

Galilea is a product of PLAN D — an independent, founder-led company with nearly 10 years of experience in AI development. No anonymous investors. No opaque structures. Just direct contact and personal accountability.

The Founders

AI Ethics

Transparency & Responsibility

Galilea operates based on high ethical standards. At a minimum, this means ensuring that AI-generated results are accurate, ethically sound, and transparent.

01

Data Quality Check

Ensures only high-quality, complete, and reliable data is fed into the AI system.

02

AI Compliance Test

Ensures all AI recommendations adhere to regulations and flags any violations.

03

Continuous Monitoring

Constant tracking of AI performance and accuracy.

04

AI Model Catalog

Transparent listing of the strengths, weaknesses, and training data sources of LLMs.

Cybersecurity

Highest Security Standards

Restricted Access
Internal access is limited to essential personnel under the principle of least privilege
Multi-Layered Security Architecture
Sustainable data protection with additional backup solutions
Consistent Security Audits
Regular, standardized reviews across all security areas
Encrypted Transmission
Data security through TLS 1.3 and HTTP Message Signatures
Encrypted Storage
AES-256 encryption ensures data protection against unauthorized access
Automated Code Scans
Continuous vulnerability analysis of the source code
Strict Data Segmentation
Tenant data is separated at the database level
No Data Used for LLM Training
AI models are used without transferring customer data
Customizable Data Retention
You control how long your data is stored
Secure Authentication
Integration with any identity provider for SSO or custom standards via 2FA and password policies
Role-Based Access Control
Define access levels for users—read or write permissions as needed
Detection of Personal Data
Real-time scanning for personal data with options for anonymization

FAQ

Your Questions, Our Answers

01
Where is Galilea hosted?

Galilea is hosted in Germany at data centers that meet the highest international security standards. The hosting infrastructure complies with certifications such as SOC 1/ISAE 3402, SOC 2, SOC 3, FISMA, DIACAP, FedRAMP, PCI DSS Level 1, ISO 9001, ISO 27001, ISO 27017, and ISO 27018. Your data remains fully within the EU.

02
How is my data secured?

Your data is fully protected during both transmission and storage. TLS 1.3 encryption secures all data transfers, while AES-256 encryption ensures protection at rest. Additionally, strict database-level separation provides an extra layer of security.

03
What personal data does Galilea process?

Galilea processes provided documents and data, as well as content from chats and search queries. The specific data types depend on your use case. Additionally, Galilea records account and usage data from employees.

04
How does Galilea anonymize or pseudonymize personal data?

Galilea detects personal data in uploaded documents using AI, automatically marks it, and provides options for anonymization, pseudonymization, or redaction.

05
Is my data used for AI training?

No, your data is never used for AI training. Your knowledge remains confidential, secure, and protected.

06
What authentication mechanisms does Galilea support?

Galilea supports integration with any identity provider (IDP) via OpenID Connect, allowing multiple IDPs simultaneously. Additionally, manual user accounts can be managed directly in Galilea. Two-factor authentication (2FA) is available for enhanced security.

07
Can Galilea employees access my data?

No, Galilea employees do not have default access to customer data. Access is technically restricted and only granted with explicit consent—for example, for support purposes. All access is logged.

08
How is my data protected against prompt injections?

Galilea prevents prompt injections through input sanitization and security filters. AI models can only access data within the user’s authorized context, ensuring unauthorized access is blocked.

ISO 27001
Enterprise-grade security
ISO 27001 (coming 2025)
German flag
KI Made in Germany
Highest standards. Clear values.
European flag
GDPR and AI Act compliant
Hosted in Europe