Security

Where your documents go, and who can compel them

Most EU-only claims describe where bytes sit and stop there. The harder question is whose courts can reach them. Both answers are on this page, including the parts that do not flatter us.

Last reviewed 2026-08-28 · reviewed again before launch

The test

Two questions, not one

1 · Where is it processed?

Residency. Which racks, in which country. This is the question every vendor answers, because it is the easy one.

2 · Who controls the processor?

Jurisdiction. A US-incorporated company can be ordered under the CLOUD Act to produce data in its possession, custody or control — including data held by a foreign subsidiary.

A vendor can pass the first and fail the second. That is the failure mode worth watching, and it catches both providers below — which is why they are listed with their owners rather than just their addresses.

Sub-processors

The chain, in full

Two providers touch documents. Both are EU-incorporated and both offer an Article 28 DPA. Neither is EU-controlled, and that distinction is the point of this table.

ProviderRole IncorporatedProcessingControlled by
Contabo GmbHHosting and compute Munich, DEGermany KKR & Co. Inc. — New York, majority since June 2022
Mistral AIModel inference for hard pages Paris, FREU endpoint Independent, France

Mistral's own sub-processors, in scope for the API

Published because a chain is only as short as its longest link. Taken from Mistral's trust centre; they list 25 in total, of which these are scoped to the API path.

Sub-processorRoleLocationNote
Mistral ComputeCloud infrastructureFrance
CoreWeave Inc.Inference providerEEAUS-incorporated
Cloudflare Inc.Traffic routingWorldwideUS-incorporated, in the request path
CrowdStrike Inc.SecurityEEA, USUS-incorporated
Ory Corp.AuthenticationBE, DE
SentryError handlingEEAUS-incorporated
Stripe Inc.BillingUSBilling metadata only
Twilio Inc.Phone verificationUSAccount data only

Two entries deserve singling out. CoreWeave is the inference provider — US-incorporated, sitting at the most sensitive point in the pipeline. Cloudflare routes Mistral's traffic worldwide, so documents transit a US company the moment they leave our box for theirs. We refuse Cloudflare's proxy in front of our own server, which removes one hop we control; it does not remove that one.

Data handling

What is kept, and for how long

Documents you send for parsing are deleted once parsing finishes. The caveat is the model provider: retention there is theirs, not ours, and the honest figure is on the right.

Documents, our serverDeleted after parsing
Documents, model provider30 rolling days
Zero-retention availableYes · their Scale plan
Training on your documentsNever
This websiteNo cookies · no analytics
Contact formGermany · deleted on request
Breach notice72 h · GDPR Art. 33
Not claimed

Four sentences you will not find on this site

Each of these is standard copy elsewhere in the category. None of them survives the two-question test above, so none of them is written anywhere on this site — including in the marketing.

The claimWhy it does not hold
“Documents never leave EU jurisdiction.” Contabo's majority owner and Mistral's inference provider are both US-incorporated.
“No CLOUD Act exposure.” A US private-equity majority holder is a weaker route to compulsion than a US hyperscaler, but it is not none.
“Sub-processors: two companies, nothing else.” Mistral's own chain adds eight more in the API path. The short list is not achievable.
“Documents deleted immediately after processing.” True on our server. Not true of the model provider below their Scale plan.

What is defensible: documents are processed in the EU by EU-incorporated contracting entities under Article 28 DPAs; no US hyperscaler holds them; the chain is short, fully disclosed, and materially shorter than Textract's or Document AI's. That is a real claim. It is just a narrower one than the category usually makes.

Found a hole in this?

Tell me. A compliance objection I have not thought of is worth more at this stage than a signup.