Security and control
Secure, controlled, and built to keep running.
Ronja puts access, known versions, visible runs, approvals, and an operating record around the systems your team builds–so control stays attached to the work after launch.
Built for the work that continues after launch.
A useful prototype proves an idea. A dependable business system also needs company context, governed data, and an operating foundation that remains visible when the first build is over.
- 01
Your rules stay explicit
The processes, edge cases, permissions, and judgment live in your business. Ronja turns that knowledge into inspectable system behavior instead of leaving it inside a prompt or a person’s memory.
How to get started - 02
Systems share governed context
Reports, workflows, agents, and applications can use the same connected data, definitions, relationships, and rules while access remains scoped to the work that needs them.
Data Foundation - 03
The operating state stays visible
Known versions, run history, approvals, and audit context give technical owners a durable view of what is running, what changed, and where intervention is needed.
Platform overview
Security at a glance
Built in hours, running for years.
The same foundation that makes systems fast to build keeps security, privacy, hosting, changes, access, and day-two operation visible after launch.
- GDPRGoverned by the DPA
- No foundation model trainingCustomer data is not used to train models
- Regional hosting & processingEU/EEA processing by default
- ISO 27001Certified
- Version control
- Access control
- Governance
- Monitoring
- Maintenance
Where data is processed. What is certified.
The published Data Processing Agreement is the contractual source for hosting, sub-processors, data use and audit evidence.
Read the DPA and sub-processor list- Infrastructure
- The DPA lists Amazon Web Services EMEA SARL for infrastructure, hosting, storage and compute in the EU.
- AI processing
- The DPA lists Anthropic via AWS Bedrock in the EU, and evroc in Stockholm, Sweden and Mougins, France, for inference. Customer data is not used to train foundation models.
- Regional controls
- EU/EEA processing is the default. The DPA lists Deep Infra in the USA only when a customer super-administrator selects a non-EU processing region. Review the configured model and region before enabling that option.
- Audit evidence
- Ronja is ISO 27001 certified; the certificate is available on request. The published DPA describes SOC 2 Type 2 attestation as in progress. Request the current certificate and audit material during procurement.
Let software do the work.Keep people in control.
Ronja combines deterministic rules, AI reasoning and human judgment depending on what the work requires.