Security

How Solheim handles your data, and the measures Annex II of the DPA commits us to.

Solheim runs open-weight language models on EU infrastructure for companies that cannot send their data to US providers. This page describes how we handle that data. It is referenced by Annex II of our Data Processing Agreement, so the measures below are contractual: we may update them, but not in a way that reduces the level of protection.

In short

  • Your prompts and outputs are not stored. They are processed in memory for the lifetime of the request and are not written to any storage system.
  • We do not train on your data. We serve open-weight models as published. Nothing you send is used to train, fine-tune or evaluate a model.
  • Inference runs in the EU only. GPU compute is in Finland, the API gateway in France. Customer Content does not leave the EU/EEA.
  • Solheim OÜ is an Estonian company, subject to EU and Estonian data protection law, acting as a Processor for the data you send.

What we process, and what we keep

Customer Content — not retained

Prompts, system prompts, uploaded context, files and model outputs pass through the gateway to a model instance and back to you. This content is held in ephemeral memory for the duration of the request and is not persisted to disk, object storage or a database. It is not written to application logs, not shared with any third party, and not used for training.

Because it is never stored, we cannot retrieve or return it — including on request. That limitation is written into section 9.4 of the DPA.

Data we do store

CategoryExamplesRetention
Account dataName, email address, organisation, hashed password or identity provider subjectLife of the account
API key metadataKey name, prefix, hash — never the key itself in plaintextUntil the key is deleted
Request metadataTimestamp, model, token counts, latency, status code, spend — no prompt or output content90 days
Billing recordsInvoices, payment references from our payment processorsAs required by Estonian accounting law
Security eventsLogin timestamps, source IP addresses for authentication events90 days

Roles

Between you and Solheim, you are the Controller and Solheim is the Processor. If you process personal data on behalf of your own customers, you are the Processor and Solheim is a Subprocessor. Both cases are covered in section 2.5 of the DPA.

Infrastructure

Hosting

GPU compute for inference runs on Verda in Finland. The API gateway, Redis and the web application run on Scaleway in France. Both are EU companies operating EU data centres. The full list of providers, with what each one does, is at /subprocessors.

Physical security, power and environmental controls at those sites are the providers' responsibility and are covered by their own certifications.

Network

All API traffic is encrypted in transit with TLS 1.2 or higher. Data at rest, including backups, is encrypted. Model instances are not exposed to the public internet; they are reachable only from the gateway over a private network.

Access control

Administrative access to production is limited to authorised personnel on a least-privilege basis, over SSH keys with multi-factor authentication on the accounts that hold them. Access is reviewed quarterly and revoked when it is no longer needed. Solheim staff do not access Customer Content; there is no tooling that would surface prompt or output content to us.

Change management and availability

Infrastructure is defined as code and can be redeployed from source. Gateway and GPU hosts are monitored with automated alerting for availability and error rates.

Incident response

We maintain a documented procedure for handling security incidents. If a Personal Data Breach affects your data, we notify you without undue delay and within 72 hours of becoming aware, with the information you need for your own Article 33 obligations. See section 7 of the DPA.

Compliance

FrameworkStatus
GDPRProcessor, EU-established. DPA published at /dpa
Estonian Personal Data Protection ActApplies; supervisory authority is the Estonian Data Protection Inspectorate
UK GDPRSupported for UK customers; UK addendum in Annex IV of the DPA
EU Standard Contractual ClausesIncorporated into the DPA for any transfer outside the EEA
EU AI ActWe provide inference for open-weight models; obligations assessed on an ongoing basis
ISO 27001Planned. Infrastructure providers hold their own certifications
SOC 2Not held

Related pages: Data Processing Agreement · Subprocessors · Privacy Policy · Terms of Service