Data security is something we care deeply about at Cobrief. That's why we have built a dedicated page that shows all the work we do on security and privacy. This includes our sub-processors, controls and certifications.
In summary, some of the key steps we take to protect our customers' data:
• Our customers own their own data.
• We never share customer data with other customers.
• Customer content, such as tender data and the documents you upload, is stored and processed only in data centers in the EU/EEA.
• All customer content uploaded to Cobrief is encrypted both in transit and at rest.
• The AI models used by Cobrief are never trained on customer data.
Our agreements
How we process data is governed by three documents:
• Terms of Service — the agreement for using Cobrief (formerly called the End User Agreement).
• Data Processing Agreement — governs customer content, such as tender data, where Cobrief is the data processor and processes the data on your behalf.
• Privacy Policy — describes operational data, such as user accounts and error logs, where Cobrief itself is the data controller.

