Security & Sovereignty

Security designed for your most critical data

Gino protects your data at every stage of its lifecycle within a trusted, secure environment built for sensitive legal operations.

Talk to an expert
Logo ISO 27001 avec globe terrestre et texte « en cours » en dessous.Icône de bouclier bleu avec un cadenas blanc entouré d'étoiles jaunes, texte RGPD avec coche.Logo de la Commission Nationale de l'Informatique et des Libertés (CNIL).Logo rond bleu avec étoiles jaunes formant un cercle autour du texte DORA blanc au centre.Badge bleu avec le texte blanc « Hébergeur certifié données de santé » et l'abréviation HDS au centre.Logo de l'Agence nationale de la sécurité des systèmes d'information (ANSSI) avec un blason stylisé bleu et rouge sur fond gris circulaire.Symbole d'un microprocesseur entouré de douze étoiles, représentant le texte « EU Artificial Intelligence Act » en dessous.Logo SecNumCloud avec une silhouette de nuage bleu et un bouclier à coche.

Security without compromise

Gino safeguards your data at every stage of its lifecycle, within a reliable, secure environment tailored to your needs

Secure Infrastructure

Trusted cloud hosting with encryption for data both at rest and in transit.

Built-in app security

Secure development practices, regular audits, and reinforced authentication (MFA, SSO).

Eye icon
Access control & full traceability

Strict role-based permissions and comprehensive audit logs for every action performed.

Compliance & recognized standards

Designed to meet GDPR, ISO 27001 and SOC 2 requirements for enterprise-grade security.

Guide

Security & Sovereignty: The practical guide to understanding and aligning with your IT team

A practical resource to help legal teams better understand security and sovereignty topics, collaborate more effectively with IT, and regain their role in strategic decision-making.
flèche blanche icon
Download the guide

Your contracts are strategic assets.
Their security should be too.

With Gino, you choose where your data is hosted and how it is protected.Azure Europe or OVHcloud: sovereignty adapted to your organization’s requirements.

Sovereign hosting, when you need it

When required, Gino can be deployed in a fully sovereign hosting environment in France via OVHcloud.This is not a default constraint — it’s an option activated according to your organization’s needs.

Two-layer security

Security at Gino goes beyond hosting infrastructure.
We combine a robust cloud environment with a security-by-design product architecture, including strict data isolation, advanced permission management, and full traceability.Security is embedded into every stage of development — not added afterward.

Controlled & configurable AI

Gino’s AI capabilities are configurable (including provider choice), can be disabled at any time, and are designed to ensure that customer data is never used for model training.Each client environment remains fully isolated.
Notre expert sécurité

"We are the sovereign CLM offering the highest level of sovereign hosting available today: SecNumCloud."

Portrait en noir et blanc d'un homme souriant avec un léger bouc, portant une chemise blanche et un pull sombre.
Amine Gharbaoui
CTO, Gino LegalTech & Ambassador of the "Dare AI" program
Our partners

Security & Sovereignty:
Checklist for evaluating a CLM

Download our practical checklist to assess the security and sovereignty level of your CLM solution: hosting, data access, compliance, and extraterritorial risks.
Discover
Resources

Additional resources

FAQ

What is data sovereignty?
Arrow

Data sovereignty refers to an organization’s ability to retain control over its data — where it is hosted, who can access it, and under which legal jurisdiction it falls.

In practical terms, this means:

  • your data is hosted in a defined country or legal area (typically within Europe)
  • it cannot be accessed by foreign authorities without an appropriate legal framework
  • you maintain control over how the data is accessed and processed

Data sovereignty goes beyond hosting alone. It also includes the providers involved, the applicable laws, and how data flows are managed.

Why is sovereignty critical in a CLM project?
Arrow

Contracts contain some of the company’s most sensitive information: intellectual property, commercial terms, strategic commitments, and confidential business data. Protecting them is therefore essential.

With regulations such as the US Cloud Act and the strengthening of European frameworks (GDPR, Data Act), questions around data access, jurisdiction, and hosting location have become strategic concerns.

Today, sovereignty is a key decision criterion in CLM projects and is often raised early in the selection process by IT and security teams (CIOs and CISOs).

Where is my data hosted with Gino?
Arrow

By default, your contracts are hosted in France on Microsoft Azure infrastructure.

For organizations with stronger sovereignty requirements, Gino also offers a fully sovereign hosting option in France via OVHcloud, certified SecNumCloud by ANSSI.

How does Gino address sovereignty requirements?
Arrow

Gino gives you full control over your hosting architecture.

You can choose between Azure or a fully sovereign infrastructure hosted in France via OVHcloud, helping reduce exposure to extraterritorial regulations and data access risks.

How does Gino protect my data?
Arrow

Security is built into the platform by design.

Your data is fully isolated, access is strictly controlled, and every action is tracked through detailed audit logs to ensure complete transparency.

Who can access my contracts?
Arrow

You control access rights according to your organization’s structure: by role, team, or entity.

Each user only has access to the data relevant to them, and every action is fully tracked through detailed audit logs.

Is AI using my data?
Arrow

No. Your contracts are never used to train AI models.

With Gino, you choose your AI provider (Mistral, OpenAI, or Microsoft), and AI features can be disabled at any time.

AI remains an assistance tool designed to support analysis, always under human supervision and control.

Should legal teams avoid free generative AI tools (e.g. free ChatGPT)?
Arrow

Yes, for any professional use involving sensitive or company data.

With most free versions, submitted data may be used to train the underlying models. From a legal and confidentiality standpoint, this creates a built-in risk by design.

Organizations should instead rely on:

  • Enterprise versions
  • Private AI environments
  • Solutions that contractually guarantee data isolation and no training on customer data (“opt-out” policies)

For legal teams handling sensitive contractual information, these guarantees are essential.

How can you verify whether an AI solution truly complies with the EU AI Act before full enforcement?
Arrow

Start by asking the provider for clear technical and transparency documentation.

A trustworthy vendor should be able to explain:

  • how the model was evaluated for bias and reliability
  • how training data was sourced
  • what safeguards are in place for security and compliance

If a provider refuses to share this information under the pretext of “trade secrets,” it should be considered a warning sign.