Third Rule
Security

Built for the most sensitive work.

Notarial and professional work combines sensitive personal data, strict accountability and real legal consequence. Third Rule is engineered for that reality: your data is protected, your decisions stay traceable, and your people stay in control.

Certifications and compliance

  • Certified

    ISO/IEC 27001:2022

    Information security management

  • In progress · Q4 2026

    SOC 2 Type II

    Security, availability and confidentiality

  • In progress · Q4 2026

    ISO/IEC 42001

    AI management systems

  • Compliant

    GDPR

    EU data protection by design

  • Compliant

    EU AI Act

    Transparency and human oversight

  • Compliant

    KNB AI-weegschaal

    Responsible AI framework for the notariaat

The Data Shield

Private data never leaves the office walls

Public AI tools send your documents somewhere else. Ours does not. The Data Shield is our own protection layer: it anonymises and encrypts every privacy-sensitive detail locally, beforeany AI ever reads it, so the intelligence reaches your desk without your clients’ identities leaving the building.

  1. 01

    It stays inside your walls

    Client data never leaves our infrastructure. Everything runs on private Microsoft Azure infrastructure in the EU, not a public cloud, and never a US-hosted one.

  2. 02

    Shielded before the AI sees it

    Locally, before any analysis, the Data Shield anonymises names, BSN numbers and other personally identifiable information using advanced NLP and RegEx filtering, and encrypts the rest with AES-256.

  3. 03

    The model reasons on abstract logic

    The AI only ever receives shielded content. It works on structure, rules and logic, never on the identities of your clients.

  4. 04

    Never used to train anything

    Shielded data is never used for the training, fine-tuning or benchmarking of any public or private AI model.

Enterprise-grade protection

Your data never trains models

Customer data is never used to train models. Not ours, and not our providers'. Your information is processed to complete your work, and for nothing else.

Encrypted end to end

Data is encrypted in transit and at rest, and sensitive information is anonymised where appropriate before it reaches a model.

European by default

Built in the Netherlands and hosted on private Microsoft Azure infrastructure in the EU, not a public cloud. GDPR compliant by design, with your data staying on European soil.

Auditable by default

Every access, model call and action is logged. Nothing happens in your environment that cannot be traced back, reviewed and explained.

Human approval for material actions

Material actions pause for human sign-off. Digital employees execute the work, while professionals stay responsible for reviewing and validating outcomes.

Built and operated in house

Our infrastructure and solutions are developed, monitored and continuously improved by Third Rule, with continuous technical monitoring behind our certified processes.

How we protect your data

  • Access control

    Role-based access and logical separation between customer environments mean only authorised people reach a given workspace. Access rights follow the principle of least privilege.

  • You own your data

    Your data remains yours. You decide what enters the environment, how long it is retained and when it is removed, and you can request export or deletion at any time.

  • Provider independence

    CLEON is model agnostic by design and selects the right technology per task. That avoids vendor lock-in and reduces dependence on any single Big Tech provider.

  • Governed by design

    Structured workflows and human approval sit around the AI, so results are dependable and every decision remains traceable and accountable.

Request our security documentation

Running a vendor assessment? We share our ISO/IEC 27001:2022 certificate, data processing agreement and security documentation with customers and prospects on request.

Third Rule B.V., security and compliance enquiries.

Request documentation