VOKT connects your entire business. That only works if security, governance and control are built into every layer, not bolted on afterwards. This page is written for your security team. Send it to them.
Data access is controlled at every step. Encrypted in transit and at rest. Isolated per customer, from a private space on shared infrastructure up to a fully sealed installation.
Policies and approvals are built in. Automations act within rules you define, and anything that needs a human decision is routed to the right human, every time.
Every question, model call, automation and action is logged. You can always trace what happened, who approved it and why. Nothing is a black box.
VOKT respects the access rules of every connected system. An answer never contains something the person asking is not allowed to see. Permissions travel with the data.
GPT, Claude, Gemini, Kimi, Mistral, open source and private models, all behind the same governance and the same permissions. You choose what runs, and where.
Shared cloud, dedicated server, your own hardware or fully sealed. Your security posture decides where VOKT runs, not the other way around.
VOKT is built and operated by Frostbyte Holding AS in Norway, with GDPR built into how we work. A data processing agreement is part of every subscription. Vokt Cloud runs in the EU. Vokt Private runs in your choice of EU or US region, so your data lives under the jurisdiction you answer to.
VOKT does not run your data through American hyperscaler platforms. For Premise deployments this is the entire point: your data never leaves your building.
Your data is exportable at any time. If you leave, everything you connected and everything you built goes with you, and your data is deleted from our infrastructure.
Not for training, not for resale, not for benchmarking, not for anything. Your data works for your business and nothing else. This holds on every tier, from Cloud to Sealed.
VOKT plugs into your identity provider. One login, centrally managed, revoked the moment someone leaves.
Roles and permissions are defined once and enforced everywhere: in search, in answers, in dashboards, in automations.
If a person cannot open a document in the source system, VOKT will not show them its contents either. Permission aware retrieval is enforced at query time, not by policy promise.
Approvals are decisions, and decisions belong to people. Automations route them to the right person and record the outcome.
When your auditor, your board or your own gut asks what happened, VOKT has the answer:
Every question, answer, automation and action, logged.
Tied to an identity, on every entry.
Answers carry their sources. Decisions carry their context.
Approvals are recorded with the person and the moment.
Every tier runs the full system with the same security model. The tiers differ in one thing only: where it runs.
Your own secure company space on VOKT's European infrastructure. Isolated per customer, operated by VOKT.
A server that runs only for you, operated by VOKT on European infrastructure. No shared tenancy at all.
Installed on infrastructure you own. Your data never leaves your walls. Deliberately not hyperscaler based.
No connection to the outside world. Local models only. Scoped with your security team, per case.
Data processing agreement with every subscription. Data residency you choose. Deletion and export on request. Your data is processed for your business and nothing else, on every tier.
The Act asks companies deploying AI for governance, human oversight, transparency and documentation. That is not a checklist VOKT bolted on, it is how VOKT works: every action governed, approvals routed to people, every answer sourced, every step logged. When your auditor asks how you control your AI, you show them the audit trail. And with European and local open source models available, you choose whose AI runs at all.
Security review coming? Good. We like companies that ask hard questions before they connect their business.
Schedule a demo, bring your hardest questions.