DataGovern

On-premise data, human decision and traceable evidence are part of the product.

DataGovern dashboard
Governance with clear accountability

Data stays local

The platform and the open-weight LLMs run in your infrastructure. No document leaves for external services.

No training on your data

Company data is used only to produce its own evidence and does not train shared models.

Human decision

The agents propose, a person approves. No obligation is filed or closed autonomously.

Traceable evidence

Every classification, gap and document is linked to the source and the regulatory text it comes from. The audit trail records analyses and approvals.

Transparency page

A dedicated section shows the models and packs in use, intended uses, allowed outbound destinations, accessibility and governance.

OISG score

Each installation computes its own OISG score from 0 to 100 with the oisg.ai criteria and issues a PDF certificate with a verification code. It is a self-assessment, not a third-party certification.

Compliance

Registers and board-ready overview

GDPR

Records of processing, a DPIA register with a template and a data subject request register with deadlines and extensions.

NIS2

The Article 21 measures register with posture by area and incident handling within the 24/72h windows.

EU AI Act

AI system inventory, linked FRIA, Annex IV technical documentation and the deployer checklist.

CRA and DORA

Dedicated registers and requirements included in the gap analysis, with applicability assessed in the compliance overview.

Board-ready compliance overview

Applicability per framework, register health, deadlines, gaps, incidents, data subject requests and AI system risk classes in one view. Exports to PDF and DOCX.

Frequently asked questions
Is DataGovern really on-premise?

Yes. The platform and the open-weight LLMs validated by noze ® are installed in your infrastructure and no document leaves for external services.

Do you use our data to train the models?

No. Company data is used only to produce its own evidence and does not train shared models.

Does DataGovern send notifications or close obligations for us?

No. It prepares evidence, registers and notifications. Filing, signature and accountability stay with the DPO or the CISO.

Which sources does DataGovern read?

Shared folders and file servers, mail, WebDAV or S3-compatible repositories and systems with REST/JSON APIs, read-only. The designated contact authorises every source and credentials are encrypted.

Does the company brain respect document permissions?

Yes. Anyone who cannot read a file at the source does not see it in DataGovern, including search, citations, versions and exports.

Can a tampered document hijack the answers?

Instructions hidden in a file can try to steer an answer (prompt injection). That is why every answer cites the document and passage and the decision stays with your team.

Which AI models does the platform use?

Only open-weight LLMs validated by noze ®, run on-premise and chosen to fit the resources of your deployment. The Transparency page shows the ones in use.

Is the OISG certificate a certification?

No, it is a self-assessment. Most points are measured automatically on the installation and the rest are attested by the designated contact: the certificate shows which is which.

What hardware is needed?

It depends on the models and the volume of documents. Servers, GPUs and storage are sized during the initial audit.

How do we start?

With an integrated GDPR, NIS2 and AI Act audit. Then the platform on an annual licence, configured to your perimeter.

Let's talk about your case

Request an audit

Need support?Under attack?Service Status
Need support?Under attack?Service Status