KI-Agenten für Produktivität und Recruitingt
Noota ist die KI-Agentenplattform, die das Recruiting beschleunigt und repetitive Aufgaben eliminiert.
ISO 27001
SOC 2 Type II
GDPR
EU datacenter
Privately hosted AI
SSO & SAML
The only meeting AI where you pick the infrastructure.
Every other platform decides for you: one cloud, one set of models, one jurisdiction.
Noota ships two complete environments and lets your security team choose the one that clears their review, without giving up a single feature.
Public bodies
Banks & insurers under DORA
Health & legal
Groups that refuse EU transfers
0
Weniger Verwaltungsaufwand

100%
MFA coverage on internal access

99.9%
Uptime on core services

2
Independent penetration tests last cycle

Two environments. Your call, not ours.
The choice is made when the workspace is created and can be changed later. Same product, same features — what changes is where it runs and which models it is allowed to reach.
standard
The default for most teams. Everything stays in the EU, with the full model range available. Outbound calls display your own number, and nothing is held back from the feature set.

sovereign
For regulated and public-sector work. European sub-processors only, open-weight models hosted in the EU, and no transfer outside the European Union at any hop. Voice runs through Telnyx, so outbound calls mask your number — the honest trade-off.

The compliance register
What we hold, what is under way, and what belongs to our providers rather than to us. Every line links to the evidence behind it.
ISO/IEC 27001
Certified — Jul 2026
Information security management. Scope: our SaaS meeting intelligence platform, across six departments.
SOC 2 Type II
Certified — 2026
Security, availability, confidentiality and privacy, evidenced over an observation period rather than at a point in time.
GDPR
Compliant — Ongoing
DPA, records of processing and a full sub-processor list. Consent management built into the product, not bolted on.
DORA
In progress — 2026
Digital Operational Resilience Act. Alignment work under way for financial-sector customers and their ICT third-party register.
EU hosting
Standard — Ongoing
Data and AI processing stay inside the European Union on both environments, with no transfer outside it in the sovereign one.
Sovereign deployment
Your choice — Ongoing
European sub-processors only, with its own security assurance plan and its own disaster recovery plan.
HDS / HIPAA
Provider-level — Ongoing
Our cloud providers hold these certifications. Noota itself does not — we host on infrastructure that meets those requirements.
Three things we never do
Most of this page describes controls. This part describes decisions — the ones that do not change with a plan, a price or a customer.
Never train
Your conversations are not used to train our models, or anyone else's, on any plan including Free. In the standard environment, frontier models are reached only through the Vertex AI gateway; in the sovereign one, open-weight models run on European infrastructure.
Never sell
No data brokerage, no advertising, no enrichment resold to a third party. Our revenue comes from subscriptions and nothing else.
Never share
Sub-processors are limited to what running the service requires, and every one of them is listed — per environment — in the trust center before you sign anything.
The controls behind it
Audited under ISO 27001, operated every day, reviewed on a schedule rather than when someone asks.
Encryption
Encrypted end to end of the pipeline
256-bit AES for data at rest, TLS 1.2 and 1.3 in transit, with keys managed in the cloud provider's KMS. Recordings, transcripts, emails and metadata are covered alike.
Isolation
Environments that never touch
Development, test and production are fully separated, and all three sit in European datacenters. No customer data ever reaches a non-production environment.
Identity
Your directory, your rules
SSO with Azure AD and SAML, automatic provisioning and de-provisioning, and role-based access on your side of the boundary.
Internal access
Least privilege, reviewed quarterly
100% MFA coverage through Google Workspace SSO, twelve-character passwords with special characters, and access rights reviewed every quarter.
Testing
Broken into on purpose
Two independent penetration tests were run over the last audit cycle, with remediation verified at re-test and no findings left open. Vulnerability scans run annually.
Continuity
Restores we have actually run
Disaster recovery plans exist in standard and sovereign versions. Point-in-time restore of the production database was last tested in July 2026. Above 99.9% uptime on core services.
Sicherheit & Compliance






