By design, not by omission.
How Deltawall is built, what it holds, how we use AI, and how to report a vulnerability. We claim no certificate we do not hold.
Five regulations. Stated, not certified.
- GDPR
- Article 5(2) accountabilityArticle 17 erasure by salt deletion
- DORA
- Payment identifiers controlled on every channel
- EU AI Act
- AI literacy (Article 4) since February 2025Transparency (Article 50) from August 2026
- Cyber Resilience Act
- 24-hour, 72-hour and 14-day reporting in the runbook
- NIS2
- Evidence verifiable without the vendor
- ISO 27001 · SOC 2
- ISO 27001 RoadmapSOC 2 RoadmapPlanned. Not claimed today.
Nothing runs below the browser sandbox.
No kernel. No TLS. No root certificate.
No drivers, no TLS termination, no root certificate. That removes fleet-outage risk and interception liability.
Extension distribution
Manifest V3, distributed through the browser stores and your enterprise install channel.
Signed builds. Separated tenants.
Signed containers, no secrets in the code, and tenant isolation enforced on every object.
Content stays on your device. Labels travel.
- Never collected
- Prompt textFilesKeystrokesScreensEncrypted traffic
- Always recorded
- Data typeSalted hashTimeDestinationChannelRuleOutcome
- Identity
- Pseudonymous tokenUnmasking needs a second approver.
- Region
- EUYour own keys on Enterprise.
- Retention
- 90 days per person, then aggregated24 months for department aggregatesBoth configurable.
- Training
- NoneNothing your people type trains anything, ever.
One small model. Nothing else.
The model is 13 MB.
It runs in the browser. It labels text; it does not generate, summarise or decide.
Three things it never does.
Send prompt content to a cloud AI service. Train on what your people write. Decide anything on its own.
The checksum wins.
A checksum match always overrides the model, and your policy picks the action.
Good-faith research is welcome.
Email security@deltawall.ai. Our PGP key and policy are at /.well-known/security.txt.
- We acknowledge within 2 business days
- We assess within 7 days
- We agree a disclosure date with you; default 90 days
- No legal action against good-faith research in scope

The reporting clock is built in.
We are a manufacturer under the Act and work to its deadlines.
24 hours
Early warning to the CSIRT and ENISA.
72 hours
Full notification: exploit, mitigations and fix.
14 days
Final report once a fix is available.
Supply chain
An SBOM for every build, dependency audit, container scanning and signed releases.
See it stop real-looking data in a real browser.
A 30-minute technical walkthrough: a prompt redacted, a file stopped, the dashboard, and an evidence pack verified offline in front of you.
No slide deck. Synthetic data only.
