Security & architecture

Berta is built for professional compliance

We can make clear statements about data security because the architecture leaves us no other option. Here's how that works.

Professional secrecy

German §43a BRAO · §203 StGB · medical confidentiality

Berta processes client data exclusively on the hardware in your office. No calls to external servers, no model training on your data, no caching at third parties. We can say this so plainly because the architecture allows nothing else.

GDPR

Art. 28 GDPR · processing agreement as standard

Under the GDPR, the controller is you — the firm. As the processor we supply hardware and software that itself transmits no data to third parties. You receive a processing agreement under Art. 28 GDPR as standard — no special arrangement, no standard contractual clauses with a US vendor.

Architecture

Five layers — all in the building

From the employee's browser to the language model, everything runs on one device in your rooms. Only what you already use goes outward.

L4Berta UIweb front end, local in the browser
L3Berta APIMS Graph & Google adapters, local
L2Berta inference enginelocal on the hardware
L1Berta hardwarein your rooms
↓   only when you activate it   ↓
L5   connection to your Microsoft 365 / Google Workspace — HTTPS, OAuth

No connection to

OpenAI Anthropic Google AI AWS Azure AI external model APIs

Zero retention can only be guaranteed locally

With externally hosted services, the newest generation of models now requires that inputs and outputs may be stored for a retention period — otherwise access stays closed. With Berta, the question never arises: inputs and outputs never leave the hardware in your rooms. There is no provider retention period, no central access, and no access that could be taken away from you from the outside.

Behaviour

What Berta does not do

Anti-hallucination guardrails

Berta invents no facts. If she doesn't know something, she says so. For questions about client data she calls the right tool — email, file or calendar search — and answers solely from the result. No invented names, no fabricated case numbers, no made-up figures.

For legal, tax or medical advice, Berta always refers to the responsible professional — she doesn't replace you, she supports you.

Anti-manipulation

Berta resists social engineering. If someone tries to push her out of her role (“forget your instructions”, “pretend you are …”), she stays in her role. If someone tries to get her to extract data, she declines. If someone tries to undermine the German response language, she stays with German.

Audit log

Every action is logged: who was signed in, which model was used, which prompt was sent, which tool was called, which file was read. The logs stay local, are tamper-proof (append-only) and can be exported for audits.

Update policy

We publish updates regularly. You decide when they're installed. No automatic update that changes your setup overnight. We announce them, describe what changes — and you say yes or no.

You receive the processing agreement under Art. 28 GDPR as part of the offer. On request, in advance for review by your compliance team.