Security

Butterflai answers questions about your business by working directly with your business data. That only works if the data is protected at every step. This page describes, in plain language, how we secure it.

Infrastructure

  • Cloud platform: Butterflai runs on Microsoft Azure, on managed Kubernetes infrastructure with container images built and deployed through a controlled CI/CD pipeline.
  • EU data residency: your business data is stored and processed inside the European Union. The platform, its databases, and uploaded files live in Microsoft Azure’s Germany West Central region (Frankfurt), and AI processing runs in Azure’s West Europe region.
  • Encryption in transit: all traffic between your browser or mobile app and Butterflai is encrypted with TLS.
  • Encryption at rest: uploaded files are stored in Azure Blob Storage, which encrypts data at rest by default.
  • Data separation: your data is scoped to your company and your users. Synced integration data, document embeddings, and files are partitioned per account, and every query runs inside that boundary.

AI processing

  • Model provider: AI language processing is performed through Azure OpenAI Service in Azure’s West Europe region, provided by Microsoft Ireland Operations Ltd. under the Microsoft Data Protection Addendum.
  • No training on your data: your data is not used to train AI models. Azure OpenAI Service does not use customer content to train models, and neither do we.
  • Observability: model interactions are traced with dedicated AI observability tooling so answer quality can be monitored and regressions investigated.

Access control

  • Authentication: secure token-based authentication, with Google sign-in supported.
  • Role-based access control: administrators assign roles that determine what each user can see and do.
  • Granular permissions: access is controlled per file, per integration, and per report. Sharing is explicit: a teammate sees a data source only when it has been shared with them directly or through their role.
  • Permission-aware AI: the AI can only retrieve what the asking user is allowed to access. Permissions are enforced at retrieval time, not just in the interface.

24/7 security monitoring

Butterflai participates in SOC4SME, the EU-funded sectoral Security Operations Center initiative operating under the aegis of the Greek Ministry of Digital Governance and the National Cyber Security Authority. Through the programme, Butterflai receives round-the-clock managed detection and response from a dedicated Security Operations Center, the same class of monitoring traditionally available only to large enterprises.

GDPR

  • Butterflai is operated by Sleed S.A., the data controller of record. Full details are in our Privacy Policy, published in 8 languages.
  • Sub-processing of AI workloads is documented in the Privacy Policy, including the Microsoft Ireland relationship.
  • You can request deletion of your account and data at any time through the account deletion page.

EU AI Act

Butterflai has been classified by external legal counsel as a limited-risk AI system under Regulation (EU) 2024/1689, the EU AI Act. The Article 50 transparency obligations that entered into application on 2 August 2026 are implemented across all three platforms: users always see that they are interacting with AI, and AI-generated reports and widgets carry a clear “AI” marking in every supported language. Our Terms of Service include an Acceptable Use Policy that prohibits using Butterflai outputs for high-risk decisions about natural persons, such as creditworthiness, insurance pricing, or employment decisions.

Reporting a vulnerability

If you believe you have found a security issue in Butterflai, contact us through the contact page and mark your message as security-related. We review every report.

Related pages: Trust Center, Platform Architecture, Connectors.