Security at Grasp

We hold the map of your AI estate. Here is exactly how we protect it.

No badge theater. This page describes what we actually do today, what is on our roadmap, and what we will show you under NDA. If a claim is on this page, we can evidence it.

// SECURITY
Data location

Where your data lives

We keep the data story specific. If a location, vendor, or encryption claim appears here, we should be able to evidence it in our architecture and DPA.

Customer data location

All customer data is stored in the EU.

Application delivery

Application delivery and edge security run through Cloudflare.

Sub-processors

Our full sub-processor list is available in our DPA. No surprise vendors, no resellers.

Encryption

Encryption in transit with TLS 1.2+ and encryption at rest with AES-256 on systems handling customer data.

Access

Who can touch your data

Customer data access is not a standing privilege. It is an exception that needs a reason, your approval, and a log.

No standing access

No Grasp employee has standing access to customer data.

Support access

Support access requires your written approval, is time-bound, and is logged.

Internal tooling

Our internal tooling sits behind zero-trust access with enforced MFA and a strict allowlist. We run the same discipline we sell.

AI data use

Your data is never training data

The AI estate data you share with Grasp is used to provide Grasp to you. It is not raw material for training models.

No training use

Customer data is never used to train, fine-tune, or evaluate AI models. Ours or anyone else's.

Greppy provider terms

For Greppy, our AI agent, we will show the model-provider terms that apply to customer data under NDA.

Contract language

We will put this in your contract, not just on this page.

Compliance

Compliance, stated precisely

We will not claim certificates, reports, or control coverage before we have the evidence. Here is the current state.

GDPR

We are a Dutch company (Traece B.V., Amsterdam) built under the GDPR from day one. Signed DPA, sub-processor list, and data subject rights handling are available on every plan.

ISO 27001

We operate our ISMS to ISO 27001 standards today and certification is on our roadmap. We can walk you through our control implementation under NDA. We will not claim the certificate before we hold it.

EU AI Act

We build EU AI Act compliance tooling, and we apply the Act's deployer obligations to our own use of AI: documented purpose, human oversight, and transparency for Greppy.

Lifecycle

Export and deletion

Your data should remain useful to you and removable when the relationship ends.

Export

One-click export of your data at any time.

Termination

On termination: full export on request, then permanent deletion after the agreed wind-down period.

Responsible disclosure

Found a vulnerability?

Email info@joingrasp.com. We respond within 2 business days and we do not pursue good-faith researchers.

Contact

Send vulnerability reports to info@joingrasp.com. Include affected URLs, reproduction steps, impact, and a safe way to contact you.

Disclosure policy

Good-faith research is welcome. Please avoid privacy violations, data destruction, service disruption, and accessing customer data.

Frequently asked

Security FAQ

Short answers only. Anything more detailed can be discussed under NDA.

TLS 1.2+ in transit, AES-256 at rest, across all systems that handle customer data.

In the EU. Sub-processor list with locations is in our DPA.

No. Never, and it is contractually excluded in our DPA.

Not yet. We operate to the standard today and certification is on the roadmap. Ask us anything about our controls; we will answer under NDA.

No one at Grasp by default. Support access requires your written approval and is fully logged.