Trust posture

Hosted in the EU. Audited per query. Reversible per release.

The questions a competent IT office asks before adopting research infrastructure — answered in one place.

Architecture

Isolation is a property of the query, not a hope about the code.

Institutional isolation in Accadema is enforced at the database query layer through a institution-aware data access pattern. Every read and every write is scoped at the data access layer; application code does not have the option of forgetting a WHERE clause. The result is that one institution cannot see another institution's data even in the presence of an application-layer bug.

Cross-institution access exists only inside an opt-in partnership and requires three explicit opt-ins: institution-level setting, user action on the specific resource, and active partnership membership. Every cross-institution event is logged with the partnership context attached. Partnership membership cache is bounded at five minutes — when an institution leaves a partnership, sessions lose access within that window.

Trust commitments

Six things we hold ourselves to.

Data residency

All Accadema-hosted production data sits in the EU. Client-hosted deployments live wherever the institution chooses.

GDPR

Data minimisation, export on request, erasure on request. Per-institutional data subject access request workflow.

Audit log

Tamper-resistant log in CAM. Every authentication event, every cross-institution access, every permission change.

Institutional isolation

Enforced at the database query layer. Cross-institution access requires three explicit opt-ins through the consortium model.

Reversible deploys

Every migration ships with a tested rollback. Every release can be rolled back inside five minutes. Backups before every migration.

No training on customer data

Athena does retrieval-augmented inference over the institution's own data; customer content is never used for model training.

Working with your security team

We are familiar with the questionnaire.

Most IT offices ask for a security questionnaire, an architecture overview, a list of subprocessors and an answer on certifications. We have a standard pack and we are happy to extend it for institution-specific compliance regimes.

For penetration testing, your local Accadema partner can coordinate a window on the production environment. For audit purposes, the audit log is exportable per institution in JSON.

Request the security pack