Adhering to ISO 27001:2022 and GDPR, on independently audited EU infrastructure.
Liffey holds the commercial knowledge your company guards most closely. The architecture was built around that from the first line of code, and it is documented control by control.
Where it runs
Every layer that stores or processes your data is inside the European Union.
- The database is managed PostgreSQL on Neon in Frankfurt (AWS eu-central-1), encrypted at rest with continuous point-in-time recovery.
- Application compute runs on Vercel serverless functions pinned to Frankfurt (fra1), so every API request is handled in-EU.
- AI inference is Claude via AWS Bedrock in eu-central-1. Embeddings are Amazon Titan Text Embeddings v2 in the same region.
- Transactional email runs through Resend in Ireland, for sign-in codes and workspace invitations.
What the model does with it
Your commercial knowledge is used to answer your questions, and for that alone.
- Every source the brain reads was chosen by a person. You and your architect nominate what goes in, and each source records who added it and how it should be treated.
- Enterprise terms with Anthropic and AWS exclude your inputs from model training.
- Zero data retention at the AI layer: prompts and responses are processed in memory.
- Liffey proposes and an owner commits. Authoritative changes to your commercial brain take effect on owner approval.
- Each session starts fresh from your knowledge base.
Who reaches it
Access is granted deliberately, recorded permanently, and expires on its own.
- Nobody at Liffey has standing access to your workspace. When support needs it, access is granted for a set time, with a reason recorded, and it expires on its own. This is the same on every tier.
- The audit log is append-only, enforced by a database grant, and records the actor, the timestamp and the before and after state of every significant action.
- Connectors read the content you authorise. Browsing and rescoping stay with the member who connected the source.
- Workspaces are invite-only. Sign-in is a one-time six-digit code to a verified address, valid for ten minutes.
What is kept, and for how long
You set the window. Liffey writes a dated summary of what mattered before anything is deleted.
- Raw transcripts, email and chat run on a retention window you set, 365 days by default. Your commercial brain, decisions and trend history sit outside it.
- Before anything is deleted, a dated summary keeps the commercial substance, and each removal is written to the audit log.
- Every workspace can enable PII redaction, replacing emails, phone numbers and bank identifiers with typed placeholders at ingestion, ahead of storage, indexing and AI processing.
- Purging a source or a document removes the record, its extracted passages and its embedding vectors together.
- Liffey holds no payment card data, national identity numbers, health data or special-category personal data.
How we know it is still true
Controls that are checked on a schedule.
- Every workspace database is checked daily through the same path the application uses, so a fault shows up the way a customer would meet it.
- If any workspace stops being checked overnight, we are alerted.
- A new high-severity vulnerability in a dependency stops the build. Dependencies are reviewed weekly.
- Access reviews run quarterly. The first was completed in August 2026.
- An incident response runbook is in place, and operational alerts fire on scan failures.
- Every web address the platform opens is checked before it is fetched, and again at every redirect, so a link cannot be used to reach systems it should not.
- Connector scopes and per-tenant secrets are encrypted at rest, and security headers are set at the edge: HSTS, content-type, frame and referrer policies.
Choose the level of separation you need.
Your workspace in the shared EU database, where every record is tagged to your workspace and every request checks that tag.
Your own database, storage, backups and at-rest encryption key, with no other customer’s data in it.
The same platform with the database inside your own cloud boundary.
On the dedicated tier the database is yours. Application compute and AI inference remain shared EU services on the same audited providers.
Certifications, and who holds them.
Every layer that stores or processes your data runs on an independently audited provider. Neon, Vercel and AWS Bedrock hold SOC 2 Type II and ISO 27001:2022, with Bedrock explicitly in scope. Anthropic adds ISO/IEC 42001:2023 for AI management systems. Resend holds SOC 2 Type II. Reports and certificates are available on request, subject to each provider’s NDA.
Liffey’s own control set is self-assessed against ISO 27001:2022 Annex A.
A client completed ISO 27001 certification with Liffey in their approved toolchain. Their auditor reviewed this architecture as part of that process.
GDPR, roles and paperwork.
You are the data controller. Liffey (Fractional Edge Limited, registered in Ireland, company number 782670) is the processor, under a standard Article 28 data processing agreement. Access, rectification, erasure, portability, restriction and objection are supported, acknowledged within 72 hours and answered within one calendar month. The core sub-processors are all in the EU: Neon, Vercel, AWS Bedrock and Resend.
Questions a security review asks.
Where does Liffey process our data?
Inside the European Union, at every layer. Managed PostgreSQL in Frankfurt on AWS eu-central-1, application compute on serverless functions pinned to Frankfurt, Claude via AWS Bedrock in eu-central-1, and Amazon Titan embeddings in the same region. Transactional email runs through Resend in Ireland.
Does Liffey train AI models on our data?
No. Enterprise terms with Anthropic and AWS exclude your inputs from model training, and the AI layer runs with zero data retention, so prompts and responses are processed in memory. Each session starts fresh from your own knowledge base.
Who at Liffey can reach our workspace?
Nobody at Liffey has standing access to your workspace. When support needs it, access is granted for a set time, with a reason recorded, and it expires on its own. This is the same on every tier. The audit log is append-only, enforced by a database grant, and records the actor, the timestamp and the before and after state of every significant action.
What certifications does Liffey hold?
Every provider that stores or processes your data is independently audited: Neon, Vercel and AWS Bedrock hold SOC 2 Type II and ISO 27001:2022, Anthropic adds ISO/IEC 42001:2023, and Resend holds SOC 2 Type II. Liffey's own control set is self-assessed against ISO 27001:2022 Annex A.
Can we run Liffey inside our own cloud?
Three hosting tiers are available: your workspace in the shared EU database with a workspace identifier on every record and scoping verified on every request; your own dedicated database, storage, backups and at-rest encryption key; or the same platform with the database inside your own cloud boundary.
How long does Liffey keep our data?
You set the window. Raw transcripts, email and chat run on a retention window you choose, 365 days by default, while your commercial brain, decisions and trend history sit outside it. Liffey writes a dated summary before anything is deleted, and each removal is written to the audit log.
Bring your security review to the call.
The architecture, the DPA and the sub-processor list are published in full, so most of a security review can be completed from what we publish and the trust centre. Security reviews reach us earlier and go deeper than they used to, and what happens when the benefit of the doubt leaves B2B buying sets out why.