Technical brief · Trust & security · July 2026

Your brain runs in Ireland.
Your data never leaves.

Seby is cloud-agnostic and hosted entirely in-region. Every deployment (the data, the memory, and the model inference) runs inside the EU, in Ireland by default. Your business data is never sent to the United States. Full GDPR compliance is built in, not bolted on.

Where everything runs

In-region, end to end

There are two things that have to stay in the EU: where your data lives, and where the AI actually thinks. With Seby, both stay in the EU, in Ireland by default. Your business data makes no round trip to the US at any point.

Your data at rest

Your business brain and its permanent memory live on an isolated machine in an Irish/EU region. One tenant per machine. Encrypted at rest and in transit.

The model inference

Claude runs in-region: Ireland on AWS Bedrock, EU endpoints on Google Vertex. Every prompt and every answer is processed inside the EU. Your data is never used to train any model.

It never leaves

Your data stays at the edge, walled to your business alone. It is never pooled with another customer, never reaches Seby, and never crosses a border.

Your Microsoft tenantMicrosoft Teams

Your team asks a question

Dublin, IrelandYour brain

Isolated machine + memory, one tenant

AWS eu-west-1, IrelandThe model

Claude reasons in-region

Your Microsoft tenantThe answer

Nothing kept at the model layer

The complete round trip of one question on the default Irish deployment. At no point does your business data cross the Atlantic.

Cloud-agnostic

Your cloud, your choice. All in-region

Seby is not locked to one provider. We deploy on Google Cloud, AWS, or Microsoft Azure, whichever your business already trusts, and we run it in that provider's Irish or EU region.

ProviderIn-region locationStatus
Microsoft AzureNorth Europe (Dublin, Ireland)Available
Amazon Web Serviceseu-west-1 (Ireland)Available
Google CloudEU regions (Belgium, Frankfurt, Paris)Available

If your data must sit on Irish soil specifically, we deploy on Azure North Europe (Dublin) or AWS Ireland, with model inference on AWS Bedrock in Ireland. If EU-wide residency is enough, any of the three works, and the model always runs on an in-region EU endpoint.

AI / LLM-agnostic

Built on Claude today. Locked to nothing.

The model is the fastest-moving part of AI, so we keep it swappable. Seby runs on Claude today because it is the strongest reasoning engine available, but every model sits behind a thin layer. The best model can be picked for each job, and a better one can be dropped in with a configuration change, not a rebuild.

Best model for each job

Different work suits different models. Seby routes each task to the model that does it best, and blends more than one where that wins.

Swap without a migration

When a stronger model arrives, a new Claude, Gemini, or whatever comes next, you move to it with a configuration change. No re-platforming, no lock-in.

Your data is model-independent

Your brain and its memory live in your own infrastructure, separate from any model. Changing the model never touches your data.

No lock-in

Your brain is yours. Leave with everything.

The fastest-moving field in software is no place for a system you cannot exit. Seby is built so the cost of leaving (us, a cloud, or a model) stays near zero. That is what makes it safe to start.

Open, portable formats

The brain is plain files and a standard database (Markdown, SQLite, git) living in your own infrastructure. No proprietary format, no black box.

Lift and shift

Everything runs on standard cloud infrastructure under version control. It can move to another provider, or in-house to your own team, without a rebuild.

Walk away whole

If you end the engagement, you keep the brain: the data, the memory, the rules and the automations. We revoke our own access and hand you the keys.

Never shared outside

Four guarantees, enforced by design

The model remembers nothing. Your brain remembers everything, in your own infrastructure, not ours and not the model's.

Compliance

GDPR, handled

Your data is processed and stored inside the EEA, so the paperwork that stalls most AI projects (transfer risk assessments, US-transfer forms, the board sign-off chase) disappears. The hardest part of GDPR for AI simply does not arise.

No US transfer to justify

Your data is stored and processed in the EEA, so there is no US cloud transfer, no transfer risk assessment and no Chapter V paperwork for your board. Where our team provides support, that access is governed by the Article 28 DPA with standard contractual clauses, the narrow, well-trodden path.

Data Processing Agreement

A GDPR Article 28 DPA covers the engagement, with a full sub-processor list and zero-data-retention terms in writing.

Your board's paperwork

We provide the DPIA, Records of Processing and a one-page sign-off pack, mapped to whatever regulatory and security sign-off your board or regulator requires.

Data-subject rights

Access, erasure and portability are supported end to end, with breach notification handled inside the 72-hour window.

Your Microsoft 365 side moved to the EU too

A common blocker is an old assessment that Microsoft's hosting, Entra ID included, sits in the United States. That ground has moved: Microsoft completed its EU Data Boundary in February 2025, and most Microsoft 365, Entra ID and Teams customer data for EU customers is now stored and processed inside the EU (a short list of excluded services remains, sourced below). If your last review of Microsoft predates that, it is worth re-running.

Security posture

Enterprise security, Microsoft-native

Microsoft-authenticated

Sign-in runs through your existing Microsoft identity, so your conditional-access and MFA policies apply unchanged.

Encrypted throughout

Encryption in transit and at rest, on infrastructure you can point to and audit.

Role-based access + audit logs

Every read is logged. Access is least-privilege and revocable at any time.

Data minimisation

The brain only ingests the data you approve. Scope it up or down whenever you like.

Enablement

Turning it on in Microsoft Teams

Your team talks to the brain inside Teams, where they already work. There are two ways your IT team can add the Seby app. This is the chat surface, how your team talks to the brain. Installing it grants no access to your Microsoft 365 data on its own. What the brain can see is a separate choice you make and control, connected source by source and revocable at any time.

Option 1

Member account

IT creates one standard Microsoft 365 user (for example seby-agent@yourdomain) that the agent signs in as to join Teams chats.

  • Your existing conditional-access and MFA policies apply
  • Full sign-in logs, like any other user
  • Removed by disabling the account

Option 2

Install the Seby app in your tenant

Your administrator installs the Seby application into your own Microsoft tenant with a single admin-consent URL. No user account is created. The app runs under its own identity, scoped to Teams chat.

App type
Multi-tenant Microsoft Entra application
Publisher
Seby (verified publisher)
Permissions
Teams chat messaging only: send and receive in conversations it is added to
No access to
Mailboxes, files, SharePoint, or your directory
Data
Nothing from your tenant is stored
Revocation
One click in Entra → Enterprise applications

The Teams app itself only sends and receives chat. Connecting data to the brain (email, meetings, files, and your line-of-business systems) is a separate, approved step, scoped exactly as you set it in "you decide what goes in" above.

Want the full architecture walkthrough?

We will take your IT and security teams through every layer, in your cloud, in Ireland.

Book a call

References

Every claim, sourced

Nothing here is our word alone. Each statement traces back to a primary source: the model providers, the cloud providers, and the regulations themselves. Sources verified July 2026.

The Claude model, hosted in the EU
Anthropic: Data residencyClaude can be deployed with EU data residency via AWS Bedrock and Google Vertex AI.
Anthropic: Claude in Amazon BedrockRunning Claude through AWS Bedrock, including EU regions.
Anthropic: Claude on Google Vertex AIRunning Claude through Google Vertex AI, including EU endpoints.
Anthropic: API & data retentionRetention policy and the zero-data-retention option.
Anthropic: Zero-data-retention agreementWhat a ZDR agreement covers.
Anthropic: Trust CenterSecurity, privacy and compliance posture, incl. no training on customer data.
Anthropic: Commercial TermsThe commercial terms under which the DPA and SCCs apply.
Anthropic: Claude regions on BedrockWhich AWS regions serve Claude, including eu-west-1 (Ireland).
AWS: Bedrock model support by RegionModel-by-region availability in Amazon Bedrock.
Data hosted in Ireland: the cloud providers
AWS: Global infrastructure: RegionsThe AWS Europe (Ireland) region, eu-west-1.
AWS: Bedrock data protectionEncryption and data handling in Amazon Bedrock.
AWS: GDPR CenterAWS GDPR compliance commitments.
Microsoft Azure: Global geographiesThe Azure North Europe region, located in Dublin, Ireland.
Microsoft Azure: Data residencyWhere Azure customer data is stored.
Microsoft: EU Data BoundaryKeeping customer data within the EU.
Microsoft: EU Data Boundary completedThe February 2025 announcement that the EU Data Boundary is complete.
Microsoft Entra: EU data storageWhere Entra ID stores and processes customer data for EU customers.
Microsoft: EU Data Boundary excluded servicesThe services not yet inside the boundary, the honest edge of the claim.
Google Cloud: LocationsGoogle Cloud regions, including europe-west in the EU.
Google Cloud: Vertex AI locationsVertex AI regional and EU endpoints.
Google Cloud: Data residencyGoogle Cloud data-residency commitments.
GDPR & data protection
EUR-Lex: GDPR, Regulation (EU) 2016/679The full official text of the GDPR.
GDPR: Article 28 (Processor)The basis for the Data Processing Agreement.
GDPR: Article 35 (DPIA)Data Protection Impact Assessments.
GDPR: Chapter V (Transfers)Rules on transfers outside the EEA, which do not apply when nothing leaves.
European Data Protection BoardThe EU body that issues binding GDPR guidance.
EDPB: Guidelines 05/2021When access from outside the EEA counts as a transfer, and why support access runs under the DPA and SCCs.
Data Protection Commission (Ireland)Ireland's data-protection regulator.
NIS2 & critical-infrastructure security
EUR-Lex: NIS2 Directive (EU) 2022/2555The EU network & information security law.
National Cyber Security Centre (Ireland)Ireland's NIS / NIS2 competent authority.
Microsoft Teams enablement
Microsoft Entra: Grant admin consentHow an administrator consents to an application in their tenant.