Berta is built for professional compliance
We can make clear statements about data security because the architecture leaves us no other option. Here's how that works.
Professional secrecy
German §43a BRAO · §203 StGB · medical confidentiality
Berta processes client data exclusively on the hardware in your office. No calls to external servers, no model training on your data, no caching at third parties. We can say this so plainly because the architecture allows nothing else.
GDPR
Art. 28 GDPR · processing agreement as standard
Under the GDPR, the controller is you — the firm. As the processor we supply hardware and software that itself transmits no data to third parties. You receive a processing agreement under Art. 28 GDPR as standard — no special arrangement, no standard contractual clauses with a US vendor.
Five layers — all in the building
From the employee's browser to the language model, everything runs on one device in your rooms. Only what you already use goes outward.
No connection to
Zero retention can only be guaranteed locally
With externally hosted services, the newest generation of models now requires that inputs and outputs may be stored for a retention period — otherwise access stays closed. With Berta, the question never arises: inputs and outputs never leave the hardware in your rooms. There is no provider retention period, no central access, and no access that could be taken away from you from the outside.
What Berta does not do
Anti-hallucination guardrails
Berta invents no facts. If she doesn't know something, she says so. For questions about client data she calls the right tool — email, file or calendar search — and answers solely from the result. No invented names, no fabricated case numbers, no made-up figures.
For legal, tax or medical advice, Berta always refers to the responsible professional — she doesn't replace you, she supports you.
Anti-manipulation
Berta resists social engineering. If someone tries to push her out of her role (“forget your instructions”, “pretend you are …”), she stays in her role. If someone tries to get her to extract data, she declines. If someone tries to undermine the German response language, she stays with German.
Audit log
Every action is logged: who was signed in, which model was used, which prompt was sent, which tool was called, which file was read. The logs stay local, are tamper-proof (append-only) and can be exported for audits.
Update policy
We publish updates regularly. You decide when they're installed. No automatic update that changes your setup overnight. We announce them, describe what changes — and you say yes or no.
You receive the processing agreement under Art. 28 GDPR as part of the offer. On request, in advance for review by your compliance team.