Trust Center

Trust by construction, not by promise.

We ask managers to let digital coworkers into Teams and into company systems. That demands concrete answers: where the data lives, who approves, what is logged, and which law applies. They are here, without adjectives.

Sovereignty

The data lives on your infrastructure.

The platform is installed on a VM of yours (on-prem or private cloud). There is no “our server” holding your data.

What stays on your VM

  • The agents (containers), charters, memory and transcripts.
  • Secrets, in a local vault; the attachments and documents agents handle.
  • The audit and usage logs.

What crosses the tunnel

  • Only Teams messages, through a zero-trust tunnel (Cloudflare) to the gateway on your VM.
  • No port open to the Internet; the VM only needs outbound HTTPS.

Model providers

  • Anthropic (Claude) and Azure OpenAI in EU regions, under their enterprise agreements (DPAs).
  • Neither provider trains models on your data.
  • Open-weight models on your VM are on the roadmap, for those who cannot send anything out.

Security controls

What the platform enforces — and what is still on the roadmap.

Every control below is live on our own installation or marked as roadmap. We don't publish controls that don't exist.

ControlHow it worksStatus
Container isolation One container per agent, with CPU and memory limits, read-only platform configuration and no access to other agents' folders. Live
Per-agent RBAC Admins, users and channels defined per agent; channel access is approved by an admin mention. Live
Secrets never pass through the model /secret NAME=VALUE is handled by the platform before the agent reads the message. The value goes to the server vault; the agent uses it only through the approved integration. Live
No cloud credentials in agents The identity that registers apps, publishes to the catalog and installs for users lives host-only. Live
Audit and usage logs Every command, grant and approval; per run: tokens, cost, duration and the model actually used. Cloud cost tracked daily. Live
Positional trust model Nothing a person writes can be read by the agent as a platform instruction — the baseline defence against prompt injection. Live
Verifiable state Agents read a machine-generated platform-state.json (version, schedules, models, seats) instead of guessing what is installed. Live
Backups and watchdogs Nightly backup of each agent's workspace; weekly install reconciliation and monthly model-deprecation checks. Live
Off-site backup Off-site backup of the installation. Roadmap
Kill switch Stop an agent in under a minute, emergency pause of the whole installation, working hours. Roadmap
Hash-chained audit Audit log export with cryptographic chaining to prove it was not altered. Roadmap

The human gate, in practice

Hiring, retiring, granting access, sending to another channel, contacting a client: none of it happens because an agent decided. The agent proposes in a card; a manager approves or rejects with a tap; the platform logs who, when and what.

It is a technical rule of the platform, not a setting someone can forget — and it is what makes every article below demonstrable to an auditor.

Chief of Staff IA
Sofia (accounts@company.pt) asked to DM Finance Admin. She is not on that agent's user list. Approve?
Grant DM access: Sofia → Finance Admin
Scope
DM only; no channels
Requested by
Sofia, today 17:42
✓ ApprovedbyAna, 17:51
Chief of Staff IA
Access granted and logged (audit #4821).
Illustrative example of an access request refused until an admin approves.

EU AI Act

Article-by-article mapping.

“AI agent” has no legal definition. Classification is by use case — and we do it in the audit, before the pilot. Most administrative roles fall outside high risk; when they don't, the mapping below is what the platform already guarantees.

ArticleWhat it requiresHow the platform answers
Art. 50 — TransparencyPeople must know they are interacting with an AI system. In force since 2 August 2026.Every agent identifies as AI in its name, app description and profile; an “AI” marker on every message (banner in each app description on the roadmap).
Art. 4 — AI literacyThose operating AI systems must have a sufficient level of literacy.“Managing AI coworkers” training (half-day) for managers, included in the pilot: briefing, approving, what not to delegate.
Art. 26 — Deployer obligationsHuman oversight, use per instructions, informing workers before use (for high-risk systems, Dec 2027).Human gate on every consequential action; adopted governance policy; worker information delivered before go-live.
Art. 12 — Record-keepingAutomatic event logs, kept for an appropriate period (≥ 6 months).Audit and per-run usage logs; ≥ 6-month retention statement in the governance pack.
Art. 14 — Human oversightMeasures so people can oversee, interrupt and override the system.Approve / Reject card, retirement by chat, per-agent model pin; kill switch on the roadmap.

Dates as per Regulation (EU) 2024/1689 and the amendments under discussion (Digital Omnibus). We re-verify quarterly; the application date for Annex III obligations is currently December 2027.

GDPR

Data protection per function, not in general.

Each agent has a concrete function; each function has a lawful basis, a purpose and a retention period. Mapping this is part of the audit and lives in the governance pack.

Lawful basis per function

For each agent we define which data it processes, on which basis (legitimate interest, contract, legal obligation) and for what. Without a clear basis, the role doesn't start.

DPIA support

A data protection impact assessment template in the governance pack, filled in with us during the audit; your DPO signs.

Art. 22 — automated decisions

The human gate is the control: no decision with effects on people is taken by the agent. It proposes; a person decides.

Art. 28 — processor agreement

We provide our DPA on request, with the subprocessor list below. Model providers have their own DPAs, which we hand over.

Erasure that reaches memory

An erasure request is applied to agent memories and transcripts, not only to databases. We document the procedure.

Retention vs audit

Audit logs are kept ≥ 6 months (AI Act Art. 12); personal data in them is minimised. We reconcile the two obligations in writing.

Certifications

What we have and what we don't.

We never say we hold a certification we don't. It is the house rule — and any auditor would confirm it in five minutes.

Now

GDPR by design

Data on your infrastructure, lawful basis per function, DPIA, DPA, effective erasure. Not a certification: it is how the platform is built.

Roadmap

ISO 27001 and SOC 2 Type II

On our roadmap. We will only publish dates when they are real. Until then, the controls above are what we can demonstrate.

Under evaluation

ISO 42001

The AI management standard is being evaluated as the framework for our governance pack.

Subprocessors

Who touches what.

The full list of third parties involved in a typical installation. Changes are communicated to clients in advance.

EntityFor whatWhere and under whatRole
AnthropicClaude models (API calls from your VM)EU / US, under Anthropic's DPA; no training on your dataModel provider
Microsoft (Azure OpenAI)OpenAI models in EU regions, when chosenEU (European regions), under Microsoft's DPAModel provider
Microsoft (Teams / Entra)Agent app registration, message deliveryYour M365 tenantCommunication platform
CloudflareZero-trust tunnel between Teams and your VM; hosting of this websiteEU / global (Cloudflare network), under Cloudflare's DPANetwork
Website analyticsStill to be decided — will be a cookieless, EU-hosted solutionEUTo be confirmed

Vulnerability disclosure

Found a flaw in the platform or on this site? Write to security@enlogical.pt. We reply within two business days, take no legal action against good-faith research, and give public credit to those who want it.

Security and privacy contact

Questions about security, the DPA or data processing: security@enlogical.pt. This website's privacy policy is at /en/legal/privacy.

Portuguese layer

The law that applies here — and how the platform answers it.

No international vendor handles this. We do, because our market is Portugal and our clients will be inspected by Portuguese authorities. Law names are kept in Portuguese; each has a short gloss.

Lei 58/2019 — beyond GDPR

Portugal's GDPR implementation law, with stricter rules on employee data and health data.

Art. 28. Employee consent is, as a rule, not a valid basis for processing their data. So each agent's lawful basis is legitimate interest or contract, documented — never “the employee agreed”.

Product commitment: agent logs are never used to evaluate employee performance. The CNPD's remote-work guidance makes monitoring software disproportionate; our logs serve the audit of the platform, not of people.

Art. 29. Health data only on a need-to-know basis, with notification of each access to the data subject. The per-access audit log is the mechanism; hosting on your VM is what closes the trust gap (see clinics).

The AI Act in Portugal

How the EU regulation is supervised nationally.

ANACOM is the national supervisory authority, coordinating 14 sector authorities. There is no national AI law or sanctions decree yet — the Regulation applies directly, and Art. 50 transparency has been in force since 2 August 2026.

ANACOM's draft guidance on prohibited practices includes emotion recognition at work. The platform doesn't do it, and won't — it is written into our governance policy as a prohibited action.

Lei 13/2023 — Código do Trabalho, Art. 106

The 2023 labour-law reform: employers must inform workers about algorithms and AI affecting work.

The employer must inform workers, the works council (comissão de trabalhadores) and union delegates about the use of algorithms and AI that affect work. Breach is a serious administrative offence, enforced by ACT (the labour inspectorate).

The governance pack delivers the notice ready before go-live: what the agents do, what they don't, who approves, how to complain. It is the practice that backs the word “colleague”, not “replacement”.

Carta Portuguesa de Direitos Humanos na Era Digital — Lei 27/2021, Art. 9

Portugal's charter of digital rights; Art. 9 covers the use of AI and robots.

Explainability, transparency, auditability and appealable decisions. Mapped one to one:

Right (Art. 9)Platform feature
ExplainabilityReadable charter for each agent; searchable transcripts of every conversation; the agent cites the source of what it states.
TransparencyAI identification on every message and in the profile; verifiable platform state (platform-state.json).
AuditabilityLog of every command, approval and cost, with the model actually used; retention ≥ 6 months.
Appealable decisionsNo consequential decision belongs to the agent: it proposes, a manager approves or rejects; immediate retirement by chat; kill switch on the roadmap.

Certified invoicing (faturação certificada)

Portuguese invoicing software must be certified by the tax authority (AT).

Agents operate your AT-certified invoicing software (Portaria 363/2010, SAF-T, ATCUD) through its APIs — Moloni, InvoiceXpress, Primavera, PHC. They prepare, match, remind.

They never issue or alter fiscal records. The certified accountant (contabilista certificado) keeps the responsibility they always had. We are not invoicing software and we don't replace the accountant: we are their right hand.

Honesty about enforcement

CNPD fines are rare (two in 2025). Warnings and stop-processing orders are not. We design for the standard, not for the fine: if a processing activity has no clear basis, the agent doesn't start.

How we deliver governance → Request the DPA and subprocessor list

Pilot in 4 weeks

Four weeks, a fixed price, an agreed KPI. At the end, the first coworker is in Teams doing real work.

A 20-minute call, a real agent at work, no slides.