SilowsilowBook a demo
Security & Trust

Your data. Your deployment. Your rules.

Silow runs where you need it to — from fully air-gapped on-prem, where your data never leaves your perimeter, to a managed pipeline that filters and deletes raw captures within 48 hours. You choose the mode. We bring the controls, the DPA, and the boundaries — so security and legal reviews take days, not months.

Deployment

Two deployment modes, two sets of privacy facts

We don't make one blanket promise about your data, because the answer depends on how you deploy. Here's exactly what's true in each mode.

01
Zero-access — self-hosted, your VPC, or on-prem

Silow runs inside the environment you control. Work data is processed in place anddoes not leave your perimeter. Silow does not access, receive, or store your raw workflow data. This is the mode for the strictest requirements.

02
Cloud-pipeline — managed by Silow (default)

Raw captures go to Silow's cloud, are filtered and anonymized server-side, anddeleted within 48 hours. Only derived patterns are kept. Here Silow acts as your data processor under an Art. 28 DPA, with a defined subprocessor list.

How capture works

It's about the work, not the worker.

Silow records how work actually happens and turns it into a map of where time goes and where AI pays back. The boundaries below are product constraints, not policy promises.

No keystroke logging

We never record what you type.

No webcam or microphone

Nothing is captured from your camera or mic.

No message content

We do not read private communications.

No individual scoring

No productivity ranking or performance evaluation.

No emotion inference

No sentiment, stress, or mood detection.

No automated decisions

Never hiring, promotion, discipline, or task allocation.

Retention

What's stored, and for how long

01
Zero-access

Raw captures never leave your environment. Only the derived insights and roadmap are produced — and they stay where you control them.

02
Cloud-pipeline

Raw captures are filtered and anonymized server-side, then deleted within 48 hours. Only the patterns are retained.

03
Deletion on request

You can request full deletion of your data and derived insights at any time.

We treat every capture as if it contains personal data.

Personally identifiable information is filtered and stripped from all data in the pipeline, and raw captures are deleted within 48 hours — so by the time your insights and roadmap exist, the personal data behind them is already gone.

Compliance

Our posture, stated honestly.

We're an early company and we won't pretend otherwise. Here's exactly where each standard stands — no badges we haven't earned.

Data processor
Silow is your processor for workflow data in cloud-pipeline mode. You stay the controller.
Today
GDPR
Art. 28 processor DPA available today, with SCCs for transfers. You stay the controller.
By design
EU AI Act
No emotion recognition, no biometric categorization, no employment scoring.
By design
SOC 2 Type II
Underway. No badge until the audit completes.
In progress

ISO 27001 is on our roadmap — planned, not started, and we say so.

Subprocessors

Who else touches your data

For managed cloud-pipeline deployments your data is processed by the two roles below — and no others. Zero-access deployments have no data subprocessors at all.

Cloud infrastructure

Hosting & processing

A major cloud provider, under a data processing agreement, certified to ISO 27001, ISO 27017 and ISO 27018 — the last one specifically for protecting personal data in the cloud. Run Silow in your own cloud account instead and this role disappears entirely.

Model inference

Filtering & anonymization

Runs the filtering and anonymization step, under a zero-data-retention policy — anddoes not train on your data.

We name the current providers in the Art. 28 DPA rather than here, because which provider fills each role depends on your deployment and its jurisdiction. Ask us for the list atteam@silow.ai — and we give you prior notice, with a window to object, before any of it changes.

Shared responsibility

What's yours to handle

Because you're the controller, some things are yours — and we make them easy.

01
Employee notices

Provide notices and obtain any consents your jurisdiction requires.

02
Works councils

German customers: complete co-determination before deployment. We ship a works-council packet with the boundaries and safeguards spelled out.

03
Your DPIA

Own it where required — we supply data-flow descriptions, technical measures, and retention limits to support it.

Practices

Security practices

Encryption in transit and at rest

Captures and derived patterns are encrypted in transit and at rest.

Least-privilege access

Scoped to the minimum each task needs — nothing broader.

SSO & SAML

Sign in through your own identity provider.

Audit logs

A record of what Silow accessed, and when.

Reviews

Built for speed.

Strong protections from day one, so security and legal reviews take days, not months. We come to the table with the deployment model, the controls, and the paperwork your security team, DPO, and legal need — including the DPA and, for regulated buyers, a zero-access path.

From signed to your first ranked roadmap in weeks, not months.