MAIA
EU SOVEREIGNTY AI

Your team wants ChatGPT. Your compliance says no.

NDAs, professional secrecy, customer requirements, export control: the obligations are real, and most AI tools cannot meet them. MAIA is built so your teams get the same capability without a single document crossing the boundaries you have committed to.

Infrastructure in Europe only Supply chain in Europe only European open-weight models Self-hosted anywhere in Europe All data stays in your country
MAIA REGION: DE
Summarise the confidentiality clauses across our three supplier NDAs.

All three run five years post-termination. Only the Meridian NDA carves out residual knowledge, which conflicts with your internal standard.

NDA_Meridian.pdf · p. 4 · v2.1 NDA_Standard_internal.docx · p. 2
Ask MAIA...
Processed in your country · no training on your data
No US subprocessor in your data path Not subject to the US CLOUD Act No AWS, no Azure, no Google Cloud
Level configurator

Two possible ways of MAIA

Pick one, or run both side by side for different needs.

Pillar 1

Managed Service

MAIA takes care of everything.

EU-only subprocessors, full transparency on every entity Hosted in certified EU data centres European LLMs, trained in Europe, for example Mistral (France) or Apertus (Switzerland) EU-hosted models, no US dependencies Updates, monitoring and backups handled by us
Pillar 2

On Premise

You run it, we support you.

Self-hosted on your own hardware or private cloud Bring your own key: your model endpoints, your contracts Bring your own infrastructure: your cloud account, your region European open-weight models of your choice, running on your side Traffic never leaves your network You keep operational control; we support the deployment

Tell us which obligations apply on your side and we will map it with you.

Map my setup
Security & compliance

The answers your security review will ask for.

Sovereignty is the headline. Underneath it sits the ordinary work of enterprise security: policies written, controls in place, evidence collected continuously.

Confidentiality

Data classification policy across every tier Data retention and disposal policy Documented disposal of customer data No training on your data

Access security

SSO via SAML and OIDC, MFA enforced Least privilege in use, administrative access restricted Document permissions inherited from your source systems

Network & endpoint security

TLS 1.3 in transit, AES-256 at rest Endpoint security on every managed device Logging and monitoring for threats

Availability & incident response

Business continuity and disaster recovery policy Backup restoration Incident response plan Tenant separation per customer

Change & vulnerability management

Secure development policy Change management policy and baseline configurations Vulnerability and patch management policy Third-party penetration test

Risk, vendors & standards

Risk register, risk assessments, vendor risk assessment Physical security policy and physical access reviews GDPR-compliant by design, EU AI Act ready ISO 27001 in final audit process

Every control above is continuously monitored and evidenced. Policies, subprocessor list, DPA and Art. 32 GDPR measures are available on request; detailed architecture documentation under NDA.

Built for

Companies where confidentiality is not optional.

You do not have to be a defence supplier for this to apply. One NDA, one research file, one customer clause is enough to make the question relevant.

Engineering IP that would be a real risk if it left the EU.

Clinical research and patient data that must be processed in-house.

Professional secrecy obligations, including § 203 of the German Criminal Code.

Export control and defence contracts that rule out cloud use entirely.

Mentioned in established media
Handelsblatt Capital MDR Startup Insider Wirtschaft in Sachsen Radio Leipzig Leipziger Zeitung The SaaS News
Certifications, associations, funding
GDPR, powered by heyData EU AI Act, powered by heyData KI Bundesverband Kofinanziert von der Europäischen Union Mitfinanziert durch Steuermittel des Sächsischen Landtags
GDPR-compliant by design EU data centres EU AI Act ready Made in DE & CH No training on your data § 203 StGB

Ready for AI that never leaves Europe?

Tell us what is at stake on your side: the contracts, the data, the obligation, and we will show you exactly how the setup could look for you.

30 minutes with our team, no obligations We answer within 3 working hours

Talk to us

One conversation with the people who build it.

Talk to us