Security is not a feature. It is the foundation.

Enterprise-grade protection, complete data sovereignty, transparent compliance, and robust governance. Deeply rooted in every layer of Kontinent.

Security Basics

Protection, data processing, and technical controls form the foundation — supplemented by comprehensible provider and contract audits.

GDPR-compliant

Customers can exercise their data rights and rely on continuous protection.

No model training

Customer data is never used to train or improve AI models.

Certificates within the scope

We verify whether a proof of compliance explicitly covers the AI service used — not just the infrastructure platform.

Encryption

Data is protected during transmission and at rest using established encryption methods.

Controls that take effect in the data stream

Security and compliance rules are enforced before the provider call — traceable, organization-wide, and restrictive by default.

Guardrails per API key

Budget limits, model and provider approvals, as well as detection of prompt injection, PII, and credentials per key.

Before the provider call

PII Redaction & Audit Log

Sensitive data is redacted in the data stream. The audit log records the organization, actor, action, and timestamp for compliance purposes.

Understandable for auditors

Policies & Deny-by-default

Custom model chains with weighting and fallback per organization. Unknown model IDs will never reach a provider.

No silent fallback

Transparent provider constraints

Limits per provider can be retrieved via the API. Prices are kept in micro-euros per model, and the catalog is continuously synchronized.

EUR-native, continuously verified

Four differences that can be verified

EU residency is being enforced

Only approved EU models can be resolved in the router. Unknown or unapproved models will be rejected before a connection is established.

Contractual requirements are code

Usage restrictions are checked during routing. A rejection refers to the specific contract clause on which it fails.

Suppliers are publicly rated

The Compliance Index follows a published methodology. Statements without a citable source are excluded — even negative findings remain visible.

Certificates are verified within the scope of application

We distinguish between existing certificates and the AI service actually covered. What is explicitly stated in the proof is decisive.

The legal foundation

No blanket promises: We verify, document, and limit what actually applies to each provider and use case.

Confirmed in writing

Seven providers confirmed the resale setup in writing — in Google's case, with a specific justification regarding the anti-resale clause.

Keys remain in the gateway

End customers do not receive provider access credentials. Kontinent remains the sole contracting party; keys do not leave the gateway.

Contracts reviewed in full text

Each provider agreement is archived with a date and checked in full text — with references to deadlines and clauses instead of website quotes.