Public AI exposes your data. SkaLean hosts everything locally.
Every request sent to ChatGPT or Copilot with customer data transits to foreign servers. In case of a GDPR audit, you cannot prove anything. SkaLean runs AI entirely in your isolated environment, with complete logs and end-to-end encryption.
What you risk every day with public AI
These three risks are real and documented. Each can cost you compliance, reputation, or customers. SkaLean eliminates them with an entirely local AI architecture.
The data that justifies action
Before and After SkaLean
Comparison of the risk and compliance profile of a 25-employee SMB before and after SkaLean deployment in sovereign mode.
Every request processed entirely locally
Your question never leaves your infrastructure. The LLM runs on your servers, logs stay with you, data remains with you.
The concrete impact on your security
Documented results from the first deployment. Zero security incidents related to AI reported by our customers.
Frequently Asked Questions
SkaLean guarantees data residency by architecture, not by contractual promise. Three technical mechanisms make it physically impossible for your data to leave your geographic perimeter:
- Local LLM execution: the language model runs on servers physically located in your datacenter or a cloud region you choose (OVHcloud Canada, AWS Canada-Central, Azure Canada East). No request is sent to American or foreign servers.
- Complete network isolation: SkaLean instances can be deployed in air-gapped mode (disconnected from the internet). In this mode, even a malicious request could not exfiltrate data because there is no network path to the outside.
- End-to-end AES-256 encryption: data is encrypted at rest and in transit with keys you control. For organizations subject to the American Cloud Act, SkaLean on Canadian or European sovereign infrastructure eliminates this risk: American authorities cannot seize data on servers not subject to their jurisdiction.
Monthly traceability report available to confirm that 0 bytes of data transited outside the perimeter.
The distinction is as much legal as technical.
Classic cloud hosting (AWS us-east-1, Azure Global): your data is physically in the United States or a region controlled by an American company. Even if the servers are in Canada, if the operator (Amazon, Microsoft, Google) is American, the US Cloud Act (2018) allows American authorities to access this data via a court order, without notifying you and without you being able to oppose it.
SkaLean sovereign hosting:
- Infrastructure operated by a Canadian or European entity (OVHcloud, Hetzner, DigitalOcean Canada) without a majority American shareholder.
- No data transits outside the chosen jurisdiction.
- The Cloud Act is not applicable.
- GDPR/Law 25 processing register maintained automatically.
What this changes for you concretely: during a GDPR audit or a Law 25 verification, you can precisely answer the question "where are your clients' personal data processed?" and prove it with logs. With classic cloud hosting, this answer is impossible or approximate.
SkaLean is designed from the ground up (privacy by design) to comply with these three regulatory frameworks.
GDPR (European Union):
- Processing register automatically maintained for each module.
- Right to erasure: any data can be permanently deleted on request, with deletion certificate.
- Right of access: export of all data linked to an individual in one click.
- Documented legal basis for each processing activity.
Law 25 (Quebec, in force since 2023):
- Privacy Impact Assessment (PIA) available on request.
- Privacy protection officer designatable in the administration interface.
- Automatic incident notifications within 72h (legal obligation).
- Logs of all personal information access.
HIPAA (United States, medical sector): SkaLean can be configured in HIPAA-compliant mode with a signable BAA (Business Associate Agreement), encryption of all PHI (Protected Health Information) at rest and in transit, and complete audit logs of medical data access.
Restriction: HIPAA compliance requires the Enterprise plan and specific configuration to validate with our team.
SkaLean applies six layers of personal data protection:
- Automatic pseudonymization: before being sent to the LLM, any identified personal data (name, email, phone number, file number) is replaced by an anonymous identifier. The LLM never sees real personal data. The generated response is re-personalized after processing.
- AES-256 encryption at rest: all stored data (documents, conversation histories, logs) is encrypted with keys derived from your tenant identifier. Even physical access to the server would not allow reading the data without the key.
- TLS 1.3 encryption in transit: all communications between your browser/application and SkaLean are encrypted.
- Multi-tenant isolation: your organization's data is strictly separated from other SkaLean clients' data at the database level (PostgreSQL Row-Level Security).
- Role-based access control: each employee only accesses data corresponding to their role. Access logs are retained for audit.
- Configurable retention period: you define how long data is retained (30 days to 7 years). Deletion is irreversible and certified.
SkaLean has a structured 5-phase incident response plan, aligned with ISO 27001 and the notification requirements of Law 25 and GDPR:
- Phase 1 — Detection (< 15 minutes): intrusion detection systems (IDS) and anomaly monitoring active 24/7. Any abnormal activity triggers an immediate alert to your security team and ours.
- Phase 2 — Containment (< 1 hour): automatic isolation of compromised components, revocation of suspicious access tokens, read-only mode activation if necessary.
- Phase 3 — Notification (< 72 hours): in compliance with GDPR and Law 25, automatic notification to your DPO/Privacy Officer and competent authorities if personal data is affected.
- Phase 4 — Investigation and restoration: complete audit log forensics (retained 12 months), root cause identification, restoration from encrypted snapshots (RPO < 1 hour, RTO < 4 hours for Enterprise plans).
- Phase 5 — Post-incident report: detailed report with timeline, extent of affected data, corrective measures implemented — directly usable for your regulatory incident report.
SkaLean offers 4-level access management, adapted for organizations of 5 to 500 people:
- Enhanced authentication: Single Sign-On (SSO) with your existing identity provider (Azure AD, Okta, Google Workspace), configurable mandatory multi-factor authentication (MFA), and time-limited sessions (60 minutes by default, configurable).
- RBAC (Role-Based Access Control): 12 predefined roles covering all typical profiles (admin, manager, operator, reader, API developer). Custom roles creatable for organizations with specific needs.
- Granular permissions by module and dataset: an employee can have access to the AI Assistant but not Studio AI, or access to HR documents but not legal documents. Permissions are managed visually without technical configuration.
- Complete audit trail: every action (login, request, modification, export, deletion) is recorded with user identity, timestamp, source IP, and action result. Logs are retained 12 months (extensible to 7 years for regulated sectors) and exportable in CSV format for your audits.
Deploy AI Without Security Risk
Our team configures the sovereign architecture, sets up audit logs, and generates your GDPR processing register. Deployment in 5 to 20 days, zero external data from day one.