BeyondCore Master Data Quality
Security & Data Protection

Built so your data never has to leave the EU.

Hosted in the EU — Frankfurt, Germany. Application and database run in Fly.io region fra. Data is processed and stored in the EU by default.
Zero Data Retention

Your raw master-data extract is processed in memory and discarded after each run. We keep only the assessment result — scores, counts, and per-finding evidence — never your records.

DLP allowlist for AI

When the AI Engine runs, only a positive allowlist of non-identifying fields is sent to the provider — never VAT/tax IDs, email, phone, bank/IBAN, credit limits or payment terms. A model must pass an eval gate before it serves real data.

Recommend-only

BeyondCore never writes back to your source systems. It suggests; a human approves. Every steward decision is recorded for audit.

Deploy your way

For full EU residency with no external AI sub-processor, run BeyondCore in your own cloud or on-premise and bring your own AI provider. Control shifts to you as your requirements rise.

Sub-processors

Every third party that may process customer data on our behalf. Kept current; the full list also lives in /legal/subprocessors.

Sub-processorPurposeDataLocation
Fly.ioHosting, compute, managed PostgreSQLAssessment results & findings. Never the raw extract.EU — Frankfurt
AnthropicAI Engine (semantic analysis)Allowlisted non-identifying fields only. No training, no retention.US
Transactional email (SMTP)Contact-form deliveryContact-form email & message only. Not master data.Configurable (EU available)

Data Processing Agreement

A DPA, ready to send.

Customer is controller, BeyondCore is processor. It reflects how we actually process data — Zero Data Retention, the DLP allowlist, EU hosting, and SCCs for the AI sub-processor. Review with your counsel and attach to the master agreement.

Download DPA template