ShareSafe FreeShareSafe WorkspaceShareSafe ConnectAI Safety AssistantHow it worksSolutionsPricingSecurity

Security

ISO 27001 certified. Built and operated in Europe.

ShareSafe operates under an ISO 27001 certified information-security management system. Workspace data is stored in the EU and managed processing takes place within the EU. Free and Workspace are deliberately described separately, because what is stored differs between them.

ISO 27001ShareSafe operates under an ISO 27001 certified information-security management system.
EU storageShareSafe Workspace files and application data are stored in the EU.
ShareSafe FreeNo account. The file utility is separate from Workspace storage. The Identity Key is not retained in the Free flow.
Audit trailProtection, access and transfer events remain connected to the file so teams can review who did what and which version was received.
Failure statesRequired protection can fail closed rather than quietly passing an unprotected file onward.

ISO 27001

Two controls ShareSafe makes much easier to implement in practice.

ShareSafe does not replace a customer's ISO programme or auditor. It gives teams a repeatable technical process and evidence for two controls that sit directly in the file flow.

A.5.14 Information transferProtect information before it moves between people, organisations and systems. Protected versions, controlled file transfers, recipient permissions and reviewable handoffs make the transfer rule operational instead of just procedural.
A.8.11 Data maskingAnonymisation and pseudonymisation reduce exposure by masking information the recipient does not need for the task.
Audit evidenceRelevant protection, access and sharing events can be retained to help demonstrate how the controls are applied.

EU AI Act

Apply better data governance before information reaches AI.

ShareSafe supports AI Act governance. It does not classify an AI system or make an organisation compliant by itself.

Data minimisationGive the AI only the information required for the task instead of the complete source document by default.
TraceabilityKeep protection and routing actions reviewable where the workflow requires evidence.
Human oversightUsers can review protected content before it is shared or sent to an approved AI route.
Controlled routesSeparate the source file and Identity Key from the model that receives the protected context.

Privacy

Security and privacy controls do not replace the customer's legal assessment.

GDPRData minimisation and pseudonymisation can be useful technical measures. Lawful processing still depends on the organisation and the use case.
HealthcareShareSafe can support controlled minimisation. It does not by itself make a clinical workflow legally compliant.