Security and data protection — from the start.
AI in the company means handling sensitive data. We take that seriously — not as a marketing promise, but as the foundation of every system.
Six principles we orient by.
Pillowcase systems are planned so data flows, access, approvals, and logs are visible from the start. These aren't promises we try to keep afterward — they're principles built into every system.
Separate systems per customer
Every customer gets their own environment. Your data isn't shared. What happens in your system stays in it.
Selected sources, not full archives
The agent works only with documents you've approved. We don't upload your entire archive. You decide what it sees.
Human approval for sensitive topics
Sensitive topics — legal content, complaints, critical cases — are flagged and forwarded to people. The agent doesn't answer them. Non-negotiable.
Agent log for traceability
Every step is logged: what was read, recognized, drafted, forwarded. You can reconstruct what happened at any time. The log is searchable.
DPA where required
Where personal data is involved, we conclude a Data Processing Agreement (DPA, German: AVV). Whether one is needed is clarified in the audit.
No legal automation
Pillowcase runs no legal automation. The agent gives no legal advice, no automated legal opinions, no automated decisions on sensitive topics. This assessment always rests with people — your team, counsel, or data protection officer.
Technical foundation, not legal advice.
Pillowcase provides the technical and organizational foundation for traceable, data-protection-aware agent operation. This is not legal advice. The final legal assessment is up to your counsel or data protection officer.
We deliberately use "GDPR-aware," not "GDPR-compliant." Whether a system is compliant in an individual case depends on factors only your counsel can authoritatively assess.
Questions about data protection? Write to us.
Data protection isn't an add-on we tack on afterward. If you have questions in advance, we take the time.