# Security facts

> The short list your security team asks for: where Adea runs, what it can do to your data, how it connects, who can sign in and what is logged.

Source: https://adea.app/docs/security-facts

The facts, one line each. The details are in [Guardian and security](/docs/guardian), and the company-level view is on the [security page](/security).

## Where your data is

- Adea and its database run in the EU.
- Your data is never used to train AI models.
- Personal values, such as names, emails, phone numbers and addresses, are replaced with stand-ins like “Person 1” before the AI model sees them. Your screen shows the real ones.
- The data processing agreement and the list of sub-processors are on the [security page](/security), and administrators accept the agreement under **Settings**, then **Agreements**.

## What Adea can do to your data

- Adea only reads. It connects with a user that can only read, checks that before it connects, and refuses a user that can write.
- Every query is checked before it runs: one plain read, nothing else.
- Adea keeps no copy of your database. It reads what a question needs, works out the answer and drops the rows. It keeps the totals behind the numbers it watches and the rows you save in a list.
- Each job runs in its own short-lived process, so one company's data never shares memory with another's.

## How Adea connects

- From fixed addresses that Adea shows when you connect a database. You allow exactly those in your firewall, and they are the same for every company. See [Connect a database](/docs/connect-database).
- To public addresses only, never to a private network.
- Passwords and tokens you give Adea are encrypted with a key that belongs to your company alone.

## Who can sign in

- People sign in with a link sent to their email, a passkey, Google or Microsoft.
- On the Business plan an administrator can require Google or Microsoft.
- Three roles decide what a person can change, and on Pro and Business an administrator can hide or mask tables and columns per role. See [Access and roles](/docs/access-and-roles).
- An AI assistant works as the person who connected it, never with more access.

## What is watched and logged

- [Guardian](/docs/guardian) checks every pull of data, whoever asks. On every plan it flags what looks unusual. On Business it can hold a request until an administrator approves.
- Weakening a protection takes a second administrator, or waits 24 hours.
- Guardian keeps a decision log and a security log. On Business you can export the log.

## Questions from your security team

Write to security@adea.app.
