Security
Where your data lives, what reaches an AI model, and who can see what.
Written for the people who have to sign off on seef. It says what happens today, including the parts that are more complicated than a diagram. If something you need is missing, email us and ask for it.
Where your data lives
Every customer gets a Google Cloud project of its own, running in europe-west1, Google's region in Belgium. The database, the file storage and the search index sit inside it, and no other customer's instance can reach into it.
Your knowledge base is a document library we set up and manage for you, hosted in our Microsoft 365 as a site of its own and shared with your team. You decide what goes into it. Most companies prefer starting this way, because a separate library means there is never a question about which documents the AI can reach. If you would rather point seef at a library inside your own Microsoft 365, tell us and we will set that up instead.
How an answer gets made
We sync your document library and build a search index inside your project. When someone asks a question, seef decides whether the question needs your documents. If it does, it looks up the passages that fit and sends the question together with those passages to the AI model configured for your instance. The answer names the documents behind it.
The database, the file storage and the search index for your instance are in Belgium. Model processing happens wherever the provider we agreed with you runs it.
Which model, and who picks it
We agree the model with you and configure it in the backend. It is set for everyone in your organisation, so what gets used stays your decision rather than each person's.
Beyond the chat model, other providers may see content, depending on what your instance uses: an embedding provider when documents are indexed or searched, a search provider if internet search is switched on, a speech provider if anyone dictates a message, an image model if anyone sends a picture, a model that maintains each person's memory of their own preferences, and Microsoft, because the document library we host for you runs on Microsoft 365. Ask us for the current list for your instance and we will give you it in writing.
Those providers are used through their commercial APIs, which is a different arrangement from the consumer apps people picture. Anthropic states it will not use inputs or outputs from its commercial products, the API included, to train its models by default. OpenAI states that data sent to its API is not used to train or improve its models unless you opt in. Neither keeps nothing at all, and it is worth knowing which: OpenAI documents abuse-monitoring retention of up to 30 days, and Anthropic documents deleting API inputs and outputs within 30 days, with exceptions in both cases.
If you would rather nothing reached a commercial AI provider at all, we can look at running an open model on infrastructure we control instead. Be clear-eyed about it: that is a build we would do with you, not a switch we flip today, and open models you can self-host sit behind Claude and GPT on answer quality while a dedicated GPU costs more than paying per call. Most companies weigh that up and prefer a frontier model under a clear agreement. We will walk you through both and you decide.
Who can see what
People sign in with your own Google Workspace or Microsoft 365 account. For your team, access is limited to your email domain, plus any individual addresses you ask us to allow. There is no extra seef password for anyone to manage. The only seef-held account on your instance is the administrator described below.
Inside your company, seef works from one shared knowledge base. Anyone who can sign in can get an answer from anything in it. seef does not mirror the permissions on the source library, and it is not built to. The control sits one step earlier: you decide what goes into the library, and that decision is what limits who can reach what. It also means the library is the wrong home for documents only part of your organisation should see.
Encryption
Traffic between your people and seef is encrypted with TLS 1.2 or better. Stored data is encrypted at rest by Google Cloud with AES-256 under Google-managed keys, which is the platform default for the database and the file storage your instance uses.
What we can reach
Your instance has one administrator account, held by one person at seef, and it exists so we can build, run and maintain the instance for you. It is the only way anyone here signs in to your instance. We do not read your documents or your conversations, and we open them when you ask us to look at something specific, and not otherwise.
That is not only a promise about how we behave: what we may do with your data is set by our agreement with you rather than left to our discretion. Being precise rather than flattering, though, it is a contractual limit and not a technical barrier. That account can reach the data, and so can the automated parts of the platform that keep your instance running. If that distinction matters to your risk assessment, tell us and we will put the controls you need in the contract.
Certifications
seef is operated by Timformatie, and Timformatie is the entity you contract with. It is certified to ISO 27001:2022 and NEN 7510-1:2024 by Brand Compliance, a certification body accredited by the Dutch Accreditation Council (RvA) under C 548. The published scope covers data consultancy, including software development, implementation and the processing of personal health information, plus support for infrastructure and hosting.
Worth stating plainly: neither is a GDPR certificate. They say an audited information security management system is in place and is checked each year by an accredited third party. They do not by themselves make any particular use of seef lawful.
Keeping and deleting
Your knowledge base stays as long as you keep it there, and your chat history stays while your subscription runs. Where memory is switched on, seef keeps a short note of each person's own preferences, stored in your instance and separate from chat history; anyone can clear their own from settings. Files someone attaches inside a conversation are removed automatically after 90 days.
Ask us to remove a user, a document or the whole instance and we do it. Removing a document from the library removes it from the index on the next sync. Removing the instance removes the cloud project it lives in, and the backups along with it.
Ask us anything else
Security questionnaires, a data processing agreement, architecture detail for an audit: send it over and we will work through it with you. Email info@seef.ai.
Last reviewed: September 2026