Home / TAOM™ Trust Center

TAOM™ Trust Center

Trust by design

Trust begins with a chain you can follow.

When AI takes part in processes, requirements, knowledge and decisions, promises are not enough. Organisations need to know: Where is the data? Which models are working? Who has access? How is AI labelled? What is logged? And which responsibility stays with people? The answers are gathered here in one place.

Not with a seal at the end. This page shows where your data is held, which tool touches it, who acts – and what of that can later be proven.

TAOM · Switzerlandapplication, database, files, backups, mail
Agent run · Frankfurtonly when an agent is started
Model providerUS by default · selectable from Enterprise
Origin and evidenceseals, log, contract documentation

Data

The normal case starts in Switzerland.

Application, database, file storage, backups and mail delivery are held at a Swiss provider. Where part of your data leaves this area, there is a nameable reason – and you find it in the next chapter.

The platform is provided by Traniva AG, based in Hittnau, canton of Zurich. Operations run with a Swiss provider whose data centre is in Lucerne.

According to the provider, the data centre is in central Switzerland and data stays in Switzerland throughout. Mail gateways are spread across Rothenburg, Rümlang and Zurich, name servers across the Swiss plateau. Access control, surveillance, CO₂ fire protection and round-the-clock monitoring come on top.

Area Location
Application Switzerland
Database Switzerland
File storage Switzerland
Backups Switzerland
Mail delivery Switzerland
AI automation n8n Cloud EU · Frankfurt
Language model OpenAI provider
All services in detail →

Operating and processing locations can differ by product, contract and provider. The details that govern a specific enterprise contract are recorded contractually.

Two legal orders, one level of protection

Switzerland is not part of the EU – for data protection that is not a drawback but an additional layer.

Swiss FADP

The revised Federal Act on Data Protection applies directly, because provider and operations are in Switzerland.

EU GDPR

For customers in the EU, processing is additionally governed by the General Data Protection Regulation – as stated in our terms.

Adequacy

The European Commission recognises Switzerland as providing an adequate level of data protection. A transfer to Switzerland therefore needs no additional safeguards such as standard contractual clauses.

Swiss platform operation

The Swiss hosting infrastructure used by Traniva is subject to Swiss law. For external AI or automation services, the legal and transfer mechanisms applying to those providers and to the respective contract configuration apply in addition.

Roles in the contract

Whether Traniva acts as controller or processor depends on the use and is settled in a separate agreement where required.

What this does not replace

A location alone is not compliance. What matters remains the configuration, the permissions and the context of use at the customer.

How customers are kept apart

What the belonging rests on

Not on a setting somebody has to maintain. Acquiring a team licence creates a key of its own for that organisation – automatically, with nothing to do.

Held on the workspace

Every workspace carries the belonging as a detail of its own. If someone moves to another organisation, their earlier workspaces do not travel with them – they stay where they belong.

For applications too

An interface access can be bound to the same belonging. A key for one organisation reaches no workspace of another, whatever it asks for.

AI

AI is an additional path – not where your work is stored.

Your models are held in Switzerland. Only when you start an agent does an extract leave that path: through the automation layer in Frankfurt to the model provider. Without an agent run this does not happen.

Data flow

What happens during an agent run?

Not the whole environment is passed on, only the content and context needed for that particular run.

TAOMWorkspace · SwitzerlandModel, role, context and permissions remain the starting point.
Automationn8n · FrankfurtServer-side orchestration. Credentials are not held in the browser.
Model providerStandard or Enterprise choiceProcessing follows the configuration applying to licence and contract.
Without an agent runModelling, importing, elaborating and exporting work without any model call.
StandardProvider, model and region follow the standard configuration and the provider’s terms.
EnterpriseProvider, hosting, region and retention can be laid down contractually.
What you enter – and what that means outside Enterprise

What you enter is your decision

The content of a request comes from the user. What is written into a prompt or handed over as process text is decided solely by the organisation using TAOM – and it is transmitted to the model provider.

Traniva does not screen this content for personal data, trade secrets or third-party rights. Screening would only be possible if we read along – and that is precisely what we do not do.

Why this matters below Enterprise

Below the Enterprise level the standard configuration applies: provider, model and processing region are preset and cannot be agreed individually. For anything you disclose through a prompt, that provider’s terms then apply.

Recommendation: outside Enterprise, do not enter personal data, secrets or anything under special supervision into prompts. If you need that, choose Enterprise – there provider, hosting and region are laid down contractually, up to operation in your own environment.

How the request runs and what the provider states

What is sent

  • What is sent the process text and its context – not the entire environment
  • Purpose Analysis, generation, classification
  • Storage and region follow the provider and its contract

What the provider states

According to OpenAI’s published information, data from the programming interface is not used to train the models by default. Inputs and outputs may be retained for a limited period for abuse monitoring.

For eligible API customers, OpenAI additionally offers zero data retention (ZDR) and regional data processing for supported configurations. These properties do not apply automatically to TAOM standard licences. They can be agreed as part of an Enterprise configuration, provided they are technically available for the models and endpoints used and enabled by the provider.

Which settings apply to your contract is confirmed in writing – we do not claim it here as a blanket statement.

With Enterprise you choose

Provider, model, hosting and processing are by agreement – including a model in your own environment or a service you already run. This is also set out in the licence terms.

That allows AI processing to sit in the same legal system as the rest of your data.

What the model makes of it

How the respective model provider technically processes inputs and which retention rules apply follows from that provider’s service and from the configuration agreed for TAOM. Traniva documents to the customer which provider is used, which data is transmitted and which contractually confirmed properties apply to the specific configuration.

For the preset models below the Enterprise level, that provider’s contractual and processing terms therefore apply. What follows from them – including in data protection terms – depends on those terms and on the applicable regulations, not on an undertaking by Traniva.

What Traniva can state: which provider is used, what is transmitted, and that credentials stay server-side. With Enterprise configurations, provider, model, hosting, processing region and retention mode can additionally be laid down contractually – up to running the model in your own environment.

Control

An agent is given permissions. Not a blank cheque.

Identity, permission, action, human approval – in that order. A machine can act, but it cannot be accountable.

Responsibility

What is the agent accountable for?

Capability

What can it carry out?

Knowledge access

Which information may it use?

Tools

Which systems may it reach?

Authority

What may it decide on its own?

Approval and output

What needs human approval, and which artefacts may it create or change?

For people

Identity → role → permission → action

For agents

Agent identity → role → authority → action → evidence

On its own

The agent acts within clearly set limits without asking.

With approval

The agent analyses or proposes – a person approves.

Never

The action is not permitted to the agent.

It has to stay answerable: who acted, in which role, with which rights, on which object, when and with what result.

Who is accountable for what

TAOM

The platform provided and the documented functions.

AI provider

Its own services under its own contract terms.

Customer

Processes, permissions, context of use and business approvals.

User

Their own authorised actions.

Agent

Carries no legal responsibility. Its authority is defined organisationally.

And therefore

Approval never sits with the agent – otherwise nobody would be accountable.

No AI in critical applications in regulated industries

The draft of the European Annex 22 on artificial intelligence limits its use in GMP-critical applications to static, deterministic models. TAOM uses language models and is expressly not intended for such applications.

Process modelling itself is not affected. Where TAOM is used in a regulated environment, AI-assisted elaboration remains a proposal that passes through your existing approval path – which is exactly how it is built.

Evidence

Not just working securely. Being able to explain later what happened.

A certificate confirms that certain criteria were examined. It does not replace what has to come first.

Every file and every document carries an origin that can be checked without access to TAOM. That is the difference between an assurance and a record.

Provenance seal on the model

Every file produced carries origin, version, time, licence state and AI label – verifiable against changes by a SHA-256 checksum with a secret key (HMAC). A foreign origin is never adopted.

Document seal on documents

Invoice, licence document, data processing agreement, certificate and contract documentation carry a number, a seal and a QR code – verifiable at taom.ai/beleg, without access to TAOM.

Four states

  • Created by people
  • AI GENERATED – produced by TAOM AI
  • AI MODIFIED – existing artefact edited in TAOM
  • Imported (unknown) – external file whose origin TAOM does not claim

What is kept on the artefact

  • Source
  • Timestamp
  • TAOM version
  • AI marker
  • Editing history
  • Licence status
  • Version

View certification and provenance →

Status per feature – in use, partly organisational, planned
Area Status
Encrypted transport in use
Credentials server-side, never in the browser in use
Identities and permissions in use
Tenant separation in use
Logging – operational log, default 30 days, configurable per environment in use
Encrypted storage partly organisational
Backup and restore in use
Network protection in use
Updates and incident handling partly organisational

“Partly organisational” means: the technical basis is in place, the evidence additionally depends on a procedure at the customer – who reviews, when and against what.

Where TAOM can support – and where not

Where TAOM can support

  • Data protection
  • AI governance
  • Internal control system
  • Process documentation in GxP settings
  • Auditability
  • Traceability
  • Enterprise governance

What that does not mean

Whether a specific use fully meets a particular regulation depends on configuration, process, organisational measures and the regulatory setting.

On the EU AI Act: TAOM provides mechanisms for transparency, traceability, human oversight and documentation – provenance, roles, authority limits, logs and versioning. There is no certification under the regulation.

View governance and compliance →

For regulated industries

Our evidence chain follows the expectations placed on computerised systems in regulated environments: timestamps in coordinated universal time, tamper-evident chaining via checksums, and attribution to the acting account through a non-speaking identifier – traceable in house, anonymous outside.

Deletions are recorded in full. Recording of creation and modification is currently being added; the status is stated in the audit report.

Enterprise

When standard is not enough, data processing becomes part of the contract.

Five routes to more sovereignty. Which one applies is examined per undertaking, enabled technically and confirmed in writing – none of it applies automatically.

EU processingprocessing in an agreed European region, where available for the services
Zero data retentionno permanent retention of request and response at the model provider configured accordingly once the processing has finished
Customer model / BYOMa provider of the customer’s own, or an existing contract
Private model hostingdedicated or customer-owned hosting, also without any outbound call
Custom data flowan individually defined processing path
Standardprovider API · no training · provider-side retention under the applicable terms
Enterprise EUagreed region for processing and data storage
Enterprise ZDRzero data retention · where technically enabled

Standard configuration: no ZDR assurance. Enterprise: ZDR possible by agreement and technical approval. Availability and scope are examined for provider, model, endpoint and region and documented in the Enterprise agreement.

What Traniva documents for each Enterprise configuration
  • the model provider in use
  • the models and endpoints used or permitted
  • the place or region of processing
  • the retention mode enabled
  • the properties assured by contract

Options include a model in your own environment without any outbound call, a Swiss provider for model processing, open models such as Apertus, developed at ETH Zurich and EPFL, or your existing contract with a provider you already use. TAOM is built so the model can be exchanged – it is a component, not a prerequisite.

What zero data retention means →

Documents

Everything procurement and data protection need – in one place.

For a security review you need documents, not promises. Contracts are the evidence layer of what is described above – here they sit together, with version number and status.

Evidence you have to be able to find

A record is only useful if it can be found when an audit comes. Because review obligation, risk, control and test result sit on the process step, the question can be asked across all models: where is something still missing – before somebody else asks?

View the attribute directory →

Which records exist and what they say
Evidence What it says Status
Person certification Three levels – Modeller, Agents, Infrastructure – each with a verifiable number in use
AI provenance on the artefact Created by people, AI-generated, AI-edited or imported in use
Validity seal on the model Held on the model and verifiable by its number in use
Document seal on documents Invoice, licence document, data processing agreement and certificate – verifiable at taom.ai/beleg in use
Contract documentation The wording of the agreements at the time of purchase, with version numbers and consent timestamps in use
Reviewed by people Approval via a ticket in the delivery system; status changes report back to the model through our own Atlassian app in use
Method compliant The model follows the TAOM rules: roles as lanes, questions at gateways, TAOM shapes partly organisational
External security certification Assessment by an independent body planned
What security reviews ask
Is customer data used to train public models?

In the current TAOM standard configuration, API content is not used for training under the published terms of the model provider in use. For differing Enterprise configurations this follows from the provider and operating model agreed. The configuration applying to the customer is documented in writing.

Where is data stored?

Depending on the operating and contract model. The governing region is recorded in the enterprise contract.

Can TAOM be used without AI?

Yes. Process Studio can be used entirely without an agent run – modelling, importing, enriching and exporting work without a single call.

Can an agent decide on its own?

Only within explicitly defined limits. Review, validation and approval stay with people.

Is TAOM certified under the EU AI Act?

No. TAOM provides mechanisms that support transparency, traceability, human oversight and documentation. There is no external certification.

Is TAOM GxP validated?

Not as a blanket statement. Whether a specific use is validated depends on the system and process context at the customer.

Verify rather than believe

Do not trust the claim. Examine what it rests on.

TAOM aims to make it traceable how data, people, agents, models, decisions and artefacts work together. If you need further documents for a security review, procurement, data protection or compliance, we put them together for your specific setup.