When you feed your technology strategy into an AI-powered tool, you're sharing some of the most sensitive information your organisation holds: your architecture, your technology choices, your risks, your roadmap. It's the kind of data that paints a complete picture of your technical capabilities and vulnerabilities.
So where that data goes matters. A lot. This post lays out the full picture — where your data is stored, where it's processed, who our sub-processors are, and how we handle the parts that involve US-incorporated vendors. No hand-waving.
The Problem With Default AI Infrastructure
Most AI-powered SaaS products route your data through US-based cloud providers and large language model APIs without much thought. The data leaves your jurisdiction, gets processed on infrastructure you have no visibility into, and may be retained for model training or improvement purposes.
For European organisations — or any company subject to GDPR, industry regulations, or simply good security hygiene — this creates real problems:
- Data processed outside the EU may not meet GDPR adequacy requirements
- You lose visibility into where your data is stored and who can access it
- Some AI providers retain input data for model training unless you explicitly opt out
- Cross-border data transfers introduce legal and compliance complexity
This isn't hypothetical risk. It's the kind of thing that keeps CISOs up at night, and rightly so.
Where Your Data Is Stored
Your nervespan workspace — your components, technologies, risks, initiatives, decisions, metrics, and everything else you build — lives in a PostgreSQL database hosted in the European Union (Supabase, running on AWS eu-west-1 in Ireland), managed for us by Supabase. Tenant isolation between organisations is enforced at the database level with row-level security policies, which we exercise with an automated test suite on every change.
We want to be straightforward about one thing: Supabase is a US-incorporated company, even though the database itself sits on EU infrastructure. That means, in principle, US data-access laws such as the CLOUD Act could apply to the provider. We think transparency about this is worth more than a marketing claim that pretends the risk doesn't exist, so we address it directly rather than around it:
- Your data is stored in the EU region, not the US
- Processing by Supabase is governed by its Data Processing Agreement, which incorporates the transfer safeguards required under UK/EU GDPR — the EU–US Data Privacy Framework where the provider is certified, with Standard Contractual Clauses and the UK International Data Transfer Addendum as the fallback mechanism
- Access to production data is restricted to authorised personnel who need it to operate and support the service — the per-provider position and our safeguards are set out on the Security & Sub-processors page
- You can export your full dataset at any time (PDF, PPTX, OPML) — there's no lock-in, and no dependency on us continuing to exist
Our full, current list of sub-processors — including their role and the region they operate in — is published on our Security & Sub-processors page.
How Your Data Is Processed by AI
When you use nervespan's AI features — extracting strategic elements from uploaded documents, generating insights, or getting recommendations — the AI inference runs on Scaleway, a French cloud provider with data centres in Paris and Amsterdam.
This was a deliberate choice:
- AI processing stays on European infrastructure, operated by a French company subject to European data protection law
- There's no US parent company behind the inference layer
- We use Scaleway's Generative APIs. Retention and non-training of prompt data at the inference layer is governed by Scaleway's contractual terms, and we do not use your prompts or outputs to train our own models
- Scaleway hosts the models on its own European infrastructure without handing your prompts off to third-party AI services
In other words, the AI layer — the part most likely to leak sensitive data to opaque US LLM APIs in a typical SaaS product — never leaves European infrastructure and never touches a US AI provider.
Data Sovereignty Is a Strategy Decision
For technology leaders, choosing tools that respect data sovereignty isn't just a compliance checkbox. It's a strategic decision that reflects how seriously you take your organisation's information security posture.
Consider what your technology strategy data includes:
- The systems you depend on and their interdependencies
- Known risks, vulnerabilities, and technical debt
- Planned initiatives and migration timelines
- Performance metrics and health indicators
- Vendor relationships and licensing details
This is effectively a blueprint of your technology estate. Sending it to opaque infrastructure with unclear data handling practices is a risk that's easy to avoid.
What to Look For in AI-Powered Tools
If you're evaluating tools that use AI to process sensitive business data, here are the questions worth asking — of us, and of anyone else:
- Where is your data physically stored, and where is AI inference physically located?
- Is your data used for model training or improvement?
- Does the provider use third-party AI APIs, and if so, which ones?
- Who are the sub-processors, and are they published?
- What data retention policies apply to AI-processed content?
- Which vendors are subject to non-EU data access laws, and how is that mitigated?
The answers should be straightforward. Ours are on the Security & Sub-processors page and in our Privacy Policy. If a vendor can't answer these plainly, that tells you something.
Privacy as a Feature, Not an Afterthought
We believe that responsible data handling shouldn't be a premium add-on or an enterprise-only feature. It should be the default. That's why every nervespan plan — from the first user to the largest team — benefits from the same EU data storage and the same European AI infrastructure.
Your technology strategy is yours. The tools you use to manage it should respect that — and should be honest with you about exactly how they handle it.
Ready to make your technology strategy operational?
nervespan helps CTOs and architects plan, manage, and communicate technology strategy with confidence.
Start Free Trial