Public previewRAGSuite is open-source, self-hosted and EU-ready — and we build it in the open.See it live

Platform Platform overviewSee it in actionAI SearchAI AssistantAI Connectors & MCPIntegrationsQuality LoopAdministration & SecurityMobile app
Solutions IT & Platform teamsCompliance & Data ProtectionDevelopersAgencies & Partners
Sovereignty
References
Pricing
Resources Trust CenterEU AI ActSecurity & disclosureFree toolsOpen source & open coreDocumentation ↗API reference ↗GitHub ↗ReferencesBlogChangelog
Company AboutPartnersContact
Search See it live Book a demo
Solutions · Compliance & data protection

GenAI you can put in front of an auditor.

Self-hosted or air-gapped, DSGVO by design, with a citation on every answer and a full audit trail. The control a DPO, a CISO and a Betriebsrat can all sign off — because nothing leaves your perimeter.

Trust Center
your-domain.de / audit logEE
09:24:01admin@acmeproject.create · “Legal KB”
09:24:18systemingest.complete · 1,204 docs
09:25:02j.webersearch.query · liability cap
09:25:02systemanswer.served · 2 citations
09:26:40admin@acmeexport.audit · CSV
The regulatory picture

Three forces push AI on-premise — the EU AI Act is only one.

Data-protection law is already here, the EU AI Act is phasing in through 2028, and the wider drive for digital independence keeps building. You don’t have to bet on a single deadline — you have to prove control whenever it’s asked of you.

  1. 2 Feb 2025

    Prohibited practices

    Banned AI uses and AI-literacy duties apply.

  2. 2 Aug 2025

    GPAI models

    Obligations for general-purpose AI models and the governance framework apply.

  3. 2 Aug 2026

    Transparency duties

    In force. Article 50 applies to providers and deployers: people must be told when they are interacting with an AI, and AI-generated content must be marked. Not limited to high-risk systems — and open-source systems are not exempt. National market-surveillance authorities can enforce from this date.

  4. 2 Dec 2026

    New prohibitions

    Two further Article 5 bans (AI nudification, AI-generated CSAM) take effect. Generative systems placed on the market before 2 August 2026 have until this date to meet the machine-readable marking requirement.

  5. 2 Dec 2027

    High-risk · standalone

    Annex III systems must comply — moved back from Aug 2026 by the Digital Omnibus on AI, Regulation (EU) 2026/1744.

  6. 2 Aug 2028

    High-risk · embedded

    AI built into regulated products (Annex I) must comply.

DSGVO by design

No data leaves your building. No new sub-processor.

Personal data stays inside your controllership and your existing processing agreements. There is no RAGSuite sub-processor to assess, because there isn’t one — the cleanest path to Art. 5, 25 and 32.

Search result on your servers
"Which clauses limit our liability under the new contract?"
Liability is capped at the total fees paid in the prior 12 months 1, and the cap does not apply in cases of gross negligence 2.
1 vertrag-2026.pdf · S. 12
2 agb.example.eu/haftung
No data left the building · 4 sources checked
The compliance gap

Two ways to answer “is this DSGVO-safe?”

One path papers over a US cloud with contracts and hope. The other removes the question by design.

GenAI on a US cloud
  • A new sub-processor your DPO must assess
  • Transfer-impact assessments and SCCs to maintain
  • Answers you can’t fully trace or audit
  • The Betriebsrat asks where the data goes
RAGSuite, self-hosted
  • No new sub-processor — data stays in your controllership
  • No cross-border transfer to justify
  • A citation on every answer, plus a full audit trail
  • Betriebsrat-friendly: nothing leaves the building
Built for due diligence

What a compliance team asks for.

Self-hosted / air-gapped

On your servers, your private cloud, or fully disconnected. Nothing phones home.

no egress

Citations & feedback

A source on every answer; feedback collection to catch what slips.

Community

Full audit & exports

Unlimited retention, severity and filters, compliance exports, legal hold.

Enterprise

Built in Germany & the EU

An innovation by NITSAN, with German service partners and DE/EN support.

DE

Every claim documented for your DPO · read the Trust Center →

Compliance you can demonstrate, line by line — not something you outsource.
The RAGSuite principle
FAQ

For compliance teams, answered

Does any data leave our environment?

No — not by default. Documents, vectors and metadata stay in your own databases; with local Ollama there is zero outbound traffic. If you use a hosted model, only the prompt you choose to send leaves.

Is it Betriebsrat-friendly?

Yes. No covert employee tracking and no external data flows to explain — the transparency that makes works-council sign-off straightforward.

What about the EU AI Act?

Prohibited-practice rules apply since Feb 2025 and GPAI duties since Aug 2025; Article 50 transparency duties have applied since 2 Aug 2026 to providers and deployers (not limited to high-risk, and open source is not exempt); high-risk obligations were deferred by the Digital Omnibus on AI, Regulation (EU) 2026/1744, to 2 Dec 2027 (standalone) and 2 Aug 2028 (embedded). Self-hosting lets you evidence compliance on your own terms. See sovereignty.

Reference
“In healthcare a wrong answer isn’t an option. Every RAGSuite answer cites its source — that’s what made it a fit for our clients.”
Brita Waldmann · pixelpublic GmbH
Read the case study
100%
cited answers
BITV
accessible
On-prem
patient-safe
DE
full UI

All references

Stefan Reinhardt, Public Sector & Compliance
Stefan Reinhardt
Public Sector & Compliance

De-risk DSGVO and the EU AI Act.

Talk to our compliance lead about your obligations — data protection, audit, and a deployment your DPO will sign off.

Founding-customer programme open now — own your AI, on your own infrastructure.
EU AI Act, explained