SaaS
We operate Colleag.ai in our Azure environment in Sweden. You use the latest LLMs through us.
- Operated in our Azure environment in Sweden
- Latest LLMs through us
- Search via Azure OpenAI within the EU
- Login and backup included
For this option
Your data. Your decisions.
You own the content. We run the platform and delete data when you ask us to.
No model training
Your product data is not used to train or fine-tune models.
Access you control
You decide who gets in. Every sign-in is logged.
Full change history
Who changed what, and why. Ready when you need to show how the work was done.
More detail for IT
Where it runs
Colleag's Azure environment in Sweden (Sweden Central). The application runs in Azure Container Apps, the database is Azure Database for PostgreSQL, and secrets live in Azure Key Vault.
Isolation between customers
Every row in the database carries its organisation's id, and the API takes the organisation from the signed sign-in token — never from anything a user can edit in an address bar. A request aimed at another organisation's resource answers that it does not exist, which also does not confirm that it does.
Encryption
TLS in transit. Stored ERP and Git credentials are encrypted with Fernet (AES-128-CBC with HMAC-SHA256) and the key lives in Key Vault, not in the code. Disks are encrypted by Azure.
Sign-in and access
Microsoft Entra External ID. You invite your users and set their role; external stakeholders can be invited with access only to what has been marked customer-visible. Every sign-in is logged.
Backups and logs
The database is backed up automatically with 35 days of history. Operational logs are kept for 30 days. You own the content and we delete it when you ask.
Your ERP
Connecting an ERP behind a firewall uses an outbound tunnel you start yourself. No inbound firewall rule, no port forward, no VPN. Colleag reads; it never writes back.
The language model
Questions, and the document extracts needed to answer them, go to Anthropic. Your data is not used to train or fine-tune models.
What we do not have
We are not ISO 27001 or SOC 2 certified. We will gladly describe how the system is built, but we have no audit certificate to show. If you need a data processing agreement, we sign one.