Trust through evidence

AI with a verifiable privacy framework

Sailrs is an AI and software agency from Stuttgart for mid-sized companies. We treat data protection as documented project scope, not a blanket promise. Whether a system meets GDPR requirements depends on data, purpose, legal basis, roles, vendors, storage locations and actual data flows.

We hold ourselves to that standard first: Sailrs is the publisher and developer of Aipe (getaipe.com), an AI operating system for European mid-sized companies. Access control, tenant isolation, deletion and the deployment model are product features we own ourselves — not assurances from a third-party vendor.

Our own product, built in Stuttgart

We publish and develop Aipe

Sailrs does not only deliver privacy-oriented AI in client projects. We publish and develop Aipe, an AI operating system for European mid-sized companies. Everything described on this page as a review framework is something we have to deliver in Aipe ourselves — as the party responsible for architecture, operations and releases.

Trust icon for publisher responsibility

Publisher and developer

Aipe is developed, published and maintained by Sailrs GmbH in Stuttgart. Architecture, security questions and roadmap are handled by the same team that delivers your project — no intermediaries in the chain of responsibility.

Security icon for access control

Roles and access

Aipe ships with fine-grained role-based access control. Which content, sources and agents a person can see is configured and traceable — a prerequisite for purpose limitation and data minimisation.

Europe icon for EU hosting and on-premise

EU hosting or on-premise

Aipe is designed to run in European cloud environments or inside your own infrastructure. Which model fits and which data flows actually occur is documented and verified per setup — see the review framework below.

Technology icon for model choice

Models without vendor lock-in

Aipe is model-agnostic: commercial providers, open-source or self-hosted models. That keeps vendor changes possible when contracts, locations or risk assessments require them.

Integration icon for system connectivity

Connected to your systems

ERP, CRM, file stores and line-of-business applications are connected through named connectors. Every connection is documented — the basis for records of processing, the DPA chain and the deletion concept.

We do not recommend anything to mid-sized companies that we would not own inside our own product.

Tjerk Dames, Sailrs GmbH

Review framework

What needs definition and verification

DPA and roles

A data processing agreement is established when Sailrs or another vendor processes personal data on a controller's behalf. Responsibilities, subprocessors, instructions and possible international transfers are named explicitly.

Technical and organizational measures

Measures may cover access control, encryption, logging, tenant isolation, recovery and incident processes. Selection and evidence depend on risk and architecture.

Deletion concept

Schedules and triggers cover inputs, outputs, vector data, logs, backups and support data. Deletion must be technically feasible and verifiable.

Operating model: EU hosting or on-premise

Both are possible building blocks, not automatic compliance guarantees. Contracts, model and infrastructure vendors, telemetry, support access and real data flows need verification for each setup. Data protection officers or legal counsel should support final assessment.

The same applies to Aipe

We ask our own product the same questions. For an Aipe deployment, legal basis, purpose, roles, connectors, model vendors, storage locations and deletion schedules are named before go-live. Product details are available under Aipe and on getaipe.com.

FAQ

Frequently asked questions about Aipe and data protection

Which AI platform does Sailrs develop itself?

Sailrs is the publisher and developer of Aipe (getaipe.com), an AI operating system for European mid-sized companies. Aipe connects existing systems, builds an enterprise knowledge graph and runs AI agents with role-based access control. Development, publishing and operations sit with Sailrs GmbH in Stuttgart.

Is Aipe GDPR compliant?

GDPR compliance is not a property of software alone but of the specific deployment. Aipe provides the required building blocks: role-based access control, tenant isolation, logging, deletion functions and deployment in European cloud or on-premise. Legal basis, purpose, DPA chain and deletion schedules are defined and documented per deployment; the final assessment should be supported by data protection officers or legal counsel.

Can Aipe run inside our own infrastructure?

Yes. Aipe is designed for deployment in European cloud environments or on-premise. Which models, connectors and telemetry are active depends on the chosen setup and is named before go-live.

Why does an in-house product matter when choosing an AI agency?

Running an AI system long term surfaces the expensive problems first-hand: model changes, access models, deletion requirements, monitoring and degrading answer quality. Sailrs runs Aipe in production and brings that experience into client projects.

Navigation