Trust
Where Galior runs, who is in the path, and what we do and do not hold — including the hops that are not in the EU.
Galior is small, and this page is written to be forwarded to someone whose job is to be sceptical of it. Everything below is either read out of our own code, checked in a provider’s dashboard on a date we name, or marked as not yet confirmed. Where we do not know, it says so.
The short version
- The application and your workspace’s database run in the EU — Ireland and Dublin.
- Durable AI runs execute in the United States, and they carry the content the AI is working on. That is true whatever residency setting you choose.
- EU residency is a setting a workspace turns on, and Galior enforces it by refusing a request it cannot serve compliantly — never by quietly using a different model.
- We hold no security certifications. We say so here rather than leaving you to notice.
What is not in the EU
Every piece of work an AI employee does in Galior runs as a durable run: it survives a crash, a redeploy, and hours of waiting while a person decides whether to approve something. That durability comes from Trigger.dev, which operates in the United States and offers no managed EU region.
A run’s payload and its logs contain the actual content being worked on — the instruction, what the AI read, what it wrote. So that content leaves the EU on every run, regardless of the residency setting. The residency setting constrains which model may be called. It does not close this hop, and no wording of ours could.
Closing it properly means running Trigger.dev ourselves inside the EU. That is possible. We have not done it, and we are not going to imply otherwise while it is still true. If this hop is what decides your evaluation, say so — it is exactly the kind of thing a first customer gets to change.
The infrastructure that is always in the path
- SupabaseIreland (eu-west-1)
Your workspace’s database and file storage: people and groups, projects, trackers, messages, sessions and their turns, uploaded files, and the sign-in itself.
Project region read from the Supabase project, 30 July 2026.
- VercelDublin (dub1)
Serves the web application and its API.
Pinned to the Dublin region in the deployment configuration committed to our repository.
- Trigger.dev CloudUnited States
Runs every durable AI run. Run payloads and logs carry the content the AI is working on — see the section above.
Trigger.dev Cloud offers no managed EU region; vendor documentation, read 30 July 2026.
- OVHcloud AI EndpointsGravelines, France · EU operator
Turns what an AI employee has learned into vectors, so it can recall the right thing later. Also the models the EU-sovereign setting resolves to.
Recorded in the product’s own model catalogue, which is the same record the residency setting reads.
- Alibaba Cloud Model Studio (Qwen)EU datacentre · China operator — production endpoint unconfirmed
The models Galior ships with by default run here.
The catalogue records the international / Frankfurt endpoint as physically EU with a non-EU operator. Galior now carries no default endpoint at all — an unset endpoint refuses the call rather than routing it somewhere nobody chose — so whatever is in production was set deliberately. Which endpoint that is has not yet been read back from the live environments, so we are not stating it.
- StripeNot yet confirmed
Payments and subscriptions, if you pay us. Card details are entered on Stripe’s own hosted pages and never reach Galior.
The hosted-checkout behaviour is verifiable in our code. The processing region of the Stripe account is not yet confirmed, so it is not stated.
- ResendNot yet confirmed
Sends the email that you, or a workflow step of yours, ask Galior to send.
Region not yet confirmed.
- UpstashNot yet confirmed
Counts requests so public endpoints can be rate limited. It holds counters and identifiers, not message content — and when it is not configured, Galior counts in memory instead.
The behaviour is verifiable in our code. The database region is not yet confirmed.
Model providers, reached only where a workspace enables them
These are not in the path by default. An administrator chooses which models a workspace may use, and a provider below is reached only if one of its models is enabled and then actually selected. What each states it does with API data is the same sentence the product shows on its model picker, so the two cannot drift apart.
- AnthropicUnited States
API data is not used for training · retained up to 30 days
Recorded in the product’s own model catalogue, which is the same record the residency setting reads.
- OpenAIUnited States
API data is not used for training · retained up to 30 days
Recorded in the product’s own model catalogue, which is the same record the residency setting reads.
- OpenRouterUnited States
A broker in front of one model that can operate a computer. Both EU settings refuse it outright.
A provider the residency filter does not recognise fails closed by construction, so it can satisfy no EU setting.
- Z.ai / ZhipuChina
Wired into our code and used for our own model comparisons. No model in the product catalogue routes to it, so a workspace cannot reach it through the product.
Verifiable in our code; listed for completeness rather than because it touches your data.
Alibaba sits in the always-on list above rather than this one, because the models Galior ships with by default run there. Turning them off is an administrator setting like any other.
Web search, reached only where a workspace turns it on
An AI in Galior can search the public web and cite what it found — but only where an administrator has switched that on, and it starts off in every new workspace. When it is on, the words being searched for go to one search company. Nothing else from the workspace is sent: not your files, not your messages, not who works there.
- MojeekUnited Kingdom
Answers a web search with page titles, links and short excerpts. Galior keeps those as the sources shown beside the AI’s answer, which is why we chose a provider whose terms permit keeping them — most do not.
Read from Mojeek’s own published API terms, which grant storage and AI use. The United Kingdom sits inside the EU adequacy decision, which runs to 27 December 2031 — that answers residency, and it does not answer sovereignty.
So a workspace set to EU sovereign does not get web search: the request is refused and says why, rather than being served from outside the EU. That is the same rule as the models below, applied to a different kind of outbound call.
A search may then lead the AI to open one of the pages it found, which Galior fetches itself, from its own servers, and which asks a person the first time each website is read. What it reads is stored with the answer.
The two EU settings, and why they are two
A workspace is set to one of three things. Off is the default: any enabled model may serve a request. EU residency allows only models whose inference physically runs in the EU. EU sovereign additionally requires that the company operating the model is itself European — today that resolves to OVHcloud, in France.
The distinction is not decoration. The Qwen models Galior ships with run in Alibaba Cloud’s Frankfurt region: physically in the EU, operated by a Chinese company. That satisfies EU residency and does not satisfy EU sovereign. Our code stores those as two separate facts — where it runs, and who operates it — and deliberately records no single “EU compliant” verdict, because the two questions have different answers and only you know which one you are being asked.
Enforced means enforced. If a workspace is set to EU sovereign and a request needs a model that can read an image, and no EU-sovereign model can read images, Galior refuses the request and says why. It does not fall back to a model that can. That behaviour has a test pinned to it, because a residency setting that silently degrades is worse than none at all.
What the setting does not do: it does not move your database, and it does not close the Trigger.dev hop above.
What we hold, and what we do not
Galior holds your workspace’s content: people and groups, projects, trackers and their items, messages, AI sessions and every turn in them, uploaded files, what your AI employees have remembered, what they spent, and the record of what they were allowed to do.
- We do not hold card numbers. Checkout and the billing portal are Stripe’s own hosted pages.
- We do not hold your password. Sign-in is handled by Supabase Auth; no Galior table contains one.
- We do not store any credential in the clear. Your own model-provider API keys, machine credentials, connected-account tokens and brokered secrets are encrypted with AES-256-GCM before they are written, and there is deliberately no plaintext path: with no encryption key configured, storing fails rather than storing in the open.
- We do not use your content to train models, and we do not sell it or share it. What the providers above do with what reaches them is stated next to each of them — read those as their commitments, not ours.
- This public site holds only what a visitor chooses to hand over on the design-partner form: a work email, plus any first name, last name, role, company or message they include, and which page it was left on. It goes into the same database as everything above, not to a form service or a mailing-list provider. A copy is sent through Resend only to alert Galior’s operator, so it adds no company to a marketing list. It is deleted after twelve months, when the conversation closes, or on request.
Encryption
In transit, everything is HTTPS. At rest, the database and file storage sit on Supabase’s managed Postgres, which encrypts data at rest — that one is Supabase’s published behaviour rather than something we implement. Secrets we hold on your behalf get the separate AES-256-GCM layer described above, on top of it.
What you control
- Which models your workspace may use, and the residency setting, in Settings → AI Models.
- Whether an AI employee has to ask a named person before it acts — set per employee and per piece of work, not once globally.
- Budget ceilings, so an AI employee cannot spend past what you gave it.
- Who can see what: sessions, files and projects each carry their own access rules, rather than everything being visible to everyone.
- Deleting a workspace. It is a soft delete with a recovery window — 30 days by default — and then a permanent purge.
What we do not claim
Galior is early. We hold no SOC 2 report, no ISO 27001 certificate and no other security certification, and you will not find one claimed anywhere on this site. We have not commissioned an external penetration test. We do not have a data processing agreement sitting on a shelf — the lists above are most of its annex, and we would rather write one properly when you need it than pretend it already exists.
Still being confirmed
Two things on this page are blanks rather than answers, and they stay blank until someone has actually looked:
- Which Alibaba Model Studio endpoint the production environment is set to. Our code no longer has a default one — an unset endpoint refuses the call instead of choosing for you — but that is a statement about the code, not a reading of the live environment.
- The processing regions of Stripe, Resend and Upstash.
We would rather leave a gap here than fill it in from memory. This page is dated, and it will change.
Ask us something specific
If you are evaluating Galior and need an answer this page does not give, ask a specific question and you will get a specific answer — including “we do not know yet”, where that is the truth. guilhem.cozier@galiorhq.com.
Last reviewed 5 August 2026.