Sovereign evidence for every scored asset.

EU-sovereign infrastructure, tenant isolation, and auditable TAS outputs for leasing-risk, board reporting, and Battery Passport readiness.

EU-sovereign by default

Compute runs on Azure Sweden Central, database stays in the EU, and TAS scoring remains deterministic. The point is not generic “AI compliance”, but evidence that stays under Finnish and EU jurisdiction.

Board-ready audit evidence

Arctura packages TAS, battery-health, and reporting outputs into a traceable evidence layer. That gives operators, risk owners, and boards something concrete to review instead of a black-box dashboard claim.

Battery Passport readiness

Battery-health snapshots, score versions, confidence fields, and limitations are documented so the same surface can support residual value work today and Battery Passport workflows next.

Alikäsittelijät (Sub-processors)

PalveluKäyttötarkoitusSijainti
Microsoft AzureCloud compute🇸🇪 Sweden Central (EU)
Mistral / Aleph AlphaEU-mode AI processing🇪🇺 EU
SupabaseDatabase, Auth🇪🇺 EU (Irlanti)
StripeMaksut🇮🇪 EU (Irlanti)
Google AI Studio (Gemini)AI (opt-in, ei PII:tä)🇪🇺 EU / 🇺🇸 Global
ResendSähköposti🇺🇸 USA (DPF)

DPA saatavilla pyydettäessä.

Control Surface

  • Tenant isolation (RLS + tenant validation)
  • Audit trail (versioned evidence outputs)
  • Auth gates (JWT + API key)
  • Application-level WAF + IP-based rate limiting
  • Restricted CORS + service boundaries
  • Runtime hardening (runAsNonRoot, drop ALL)
  • Semgrep SAST + Trivy CI
  • Documented DPA and sub-processor list
  • SOC 2 Type II — Planned H2 2026
  • ISO 27001 — Planned H2 2026
Pyydä trust pack →
NeurFlow Oy · Y-tunnus 3597951-1 · Helsinki, Suomi

Need the full Security & Integration Proof Pack?

Architecture overview, data residency confirmation, WAF/RLS details, and SOC 2 roadmap — delivered to your CISO or DPO.

Request Proof Pack →