Early access is open for EU organisations protecting 100 or more users.Get Early Access
Deltawall
Trust and security

By design, not by omission.

How Deltawall is built, what it holds, how we use AI, and how to report a vulnerability. We claim no certificate we do not hold.

Standards

Five regulations. Stated, not certified.

GDPR
Article 5(2) accountabilityArticle 17 erasure by salt deletion
DORA
Payment identifiers controlled on every channel
EU AI Act
AI literacy (Article 4) since February 2025Transparency (Article 50) from August 2026
Cyber Resilience Act
24-hour, 72-hour and 14-day reporting in the runbook
NIS2
Evidence verifiable without the vendor
ISO 27001 · SOC 2
ISO 27001 RoadmapSOC 2 RoadmapPlanned. Not claimed today.
Posture

Nothing runs below the browser sandbox.

No kernel. No TLS. No root certificate.

No drivers, no TLS termination, no root certificate. That removes fleet-outage risk and interception liability.

Extension distribution

Manifest V3, distributed through the browser stores and your enterprise install channel.

Signed builds. Separated tenants.

Signed containers, no secrets in the code, and tenant isolation enforced on every object.

Data handling

Content stays on your device. Labels travel.

Never collected
Prompt textFilesKeystrokesScreensEncrypted traffic
Always recorded
Data typeSalted hashTimeDestinationChannelRuleOutcome
Identity
Pseudonymous tokenUnmasking needs a second approver.
Region
EUYour own keys on Enterprise.
Retention
90 days per person, then aggregated24 months for department aggregatesBoth configurable.
Training
NoneNothing your people type trains anything, ever.
How we use AI

One small model. Nothing else.

The model is 13 MB.

It runs in the browser. It labels text; it does not generate, summarise or decide.

Three things it never does.

Send prompt content to a cloud AI service. Train on what your people write. Decide anything on its own.

The checksum wins.

A checksum match always overrides the model, and your policy picks the action.

Responsible disclosure

Good-faith research is welcome.

Email security@deltawall.ai. Our PGP key and policy are at /.well-known/security.txt.

  • We acknowledge within 2 business days
  • We assess within 7 days
  • We agree a disclosure date with you; default 90 days
  • No legal action against good-faith research in scope
A clean desk with a closed laptop in a bright room.
Cyber Resilience Act

The reporting clock is built in.

We are a manufacturer under the Act and work to its deadlines.

1

24 hours

Early warning to the CSIRT and ENISA.

2

72 hours

Full notification: exploit, mitigations and fix.

3

14 days

Final report once a fix is available.

4

Supply chain

An SBOM for every build, dependency audit, container scanning and signed releases.

Get started

See it stop real-looking data in a real browser.

A 30-minute technical walkthrough: a prompt redacted, a file stopped, the dashboard, and an evidence pack verified offline in front of you.

No slide deck. Synthetic data only.

The VU Amsterdam campus in the Zuidas at blue hour, lit windows reflected in a wet plaza with bicycles parked out front.
Where we are

Built in Amsterdam, at VU StartHub.

Deltawall works from VU StartHub, the startup hub of Vrije Universiteit Amsterdam, on campus in the Zuidas. Meet the team for a demo in person.

VU StartHub, NU Building
De Boelelaan 1111
1081 HV Amsterdam, the Netherlands