This page shows where our servers run, which suppliers process data for us, and what we do to protect it. The supplier list is built from the systems that are actually running — not written by hand.
One shared set of controls for all our products, inspired by ISO 27001. We only say «in place» when it is true today.
| Control | Status | What it means | How we know |
|---|---|---|---|
| Hosting in the EU | In place | All our own services run on servers in Stockholm. | Read from every running service, 27 September 2026. |
| Encryption | In place | All traffic is encrypted (HTTPS/TLS). Disks and databases are encrypted by the hosting provider. | HTTPS on all our domains; encrypted storage is the default at Fly.io and Supabase. |
| Two-factor sign-in | In place | Single sign-in (Broberg ID) with passkeys and two-factor. Being rolled out to all products. | Built into Broberg ID. |
| Incident response plan | In place | A written plan. If we process data on your behalf, you hear from us within 24 hours. The Danish Data Protection Agency is notified within 72 hours where we are the controller. | Plan approved by management, 27 September 2026. |
| Backups | In progress | Daily copies, kept for 30 days. We are moving all copies to storage locked to the EU and introducing a monthly automated test that a copy can be restored. | 30-day retention read from every data disk, 27 September 2026. |
Write to security@broberg.ai. We reply within one business day. Machine-readable contact: /.well-known/security.txt.
Web House ApS · Danish company reg. (CVR) 21221198 · Riberhusvej 9, 9492 Blokhus, Denmark
Sub-processors in production, and where the instance we use runs. «Measured» means we read it from our own setup; the rest comes from the supplier's own pages. Every supplier outside the EU is covered by an EU-approved transfer mechanism. A new supplier is listed here at least 30 days before we start using it.
| Supplier | Used for | Where data lives | Company | Transfer |
|---|---|---|---|---|
| Fly.io | Hosting of our services | Stockholm · measured | USA | EU-US Data Privacy Framework |
| GatewayAPI | SMS codes at sign-in | Denmark, Germany, Finland | Denmark | Within the EU |
| Microsoft Azure | Speech-to-text and text-to-speech | Western Europe | USA | EU-US Data Privacy Framework |
| Mistral AI | AI language models (our default) | France | France | Within the EU |
| Simply.com | Domains | Denmark | Denmark | Within the EU |
| Supabase | Database and sign-in | Stockholm · measured | USA | EU standard contractual clauses |
| Supplier | Used for | Where data lives | Company | Transfer |
|---|---|---|---|---|
| Cloudflare | Domains, DNS, file storage and spam protection | File storage: EU · DNS and network: global · measured | USA | Data Privacy Framework + standard clauses |
| Resend | Sending email | Sent from Ireland · mail metadata in the US | USA | Data Privacy Framework + standard clauses |
| Stripe | Payments | Contract in Ireland · may be processed globally | USA | Data Privacy Framework + standard clauses |
| Tigris | File storage and backups | Moving to the EU (in progress) · measured | USA | EU standard contractual clauses |
| Supplier | Used for | Where data lives | Company | Transfer |
|---|---|---|---|---|
| Anthropic | AI models | United States | USA | EU standard contractual clauses |
| ElevenLabs | Text-to-speech (podcast) | United States | USA | Data Privacy Framework + standard clauses |
| fal.ai | Image generation | United States | USA | EU standard contractual clauses |
| GitHub | Source code and automated deployment | United States | USA | Data Privacy Framework + standard clauses |
| Google Firebase | Push notifications to apps | Global | USA | Data Privacy Framework + standard clauses |
| Google Gemini | AI models (fallback) | United States | USA | EU-US Data Privacy Framework |
| Google Workspace | Email, calendar and sign-in | Global | USA | Data Privacy Framework + standard clauses |
| OpenAI | AI models | United States | USA | EU standard contractual clauses |
| OpenRouter | Access to AI models, incl. images (Recraft) | United States | USA | EU standard contractual clauses |
| Vimeo | Video | United States | USA | Data Privacy Framework + standard clauses |
List last changed 27 September 2026.
Aidan is broberg.ai's own AI guide — built on the house components with this whole universe as its knowledge base. Answers may contain mistakes.
Aidan wasn't bought in — he grew up here. The name is AI + Denmark: built in Aalborg, answering in Danish and English, with his data staying in Europe. He learned his trade from the house's own flagships — the project manager that verifies every promise, the memory that remembers why, and the ever-watchful teammate that catches mistakes before the customer does. Airina is the same brain with a different voice and face. Read Aidan's full story.
Aidan runs on the house's own components — the same technology we build customer solutions with. The language comes from a European AI model, the voices are neural voices, and everything runs on servers in the EU.
The chat is answered by an AI model hosted in Paris — no American models are involved in the conversation. Readings are generated and stored on our own European servers. Your email is only used if you ask to have an audio file sent, and only with your explicit consent.
The conversation is stored solely in your own browser — not on our server, and never alongside anyone else's. Every message you send carries only your own conversation, so users' chats are hermetically sealed from each other. Aidan also cannot fetch data from the internet: he mechanically has no access to anything beyond the knowledge base we've given him — and that barrier is sealed with a test, so it can't be removed silently.
Everything you see here — the chat, the read-aloud, the site itself — is built and run by the same AI tools we deliver to customers. We use them ourselves every day and improve them continuously, so what you're looking at isn't a demo: it's our own working toolset.
Aidan is an AI — answers may contain mistakes.