Trust Center
Built to be
private.
Our agents run on your enterprise AI and TP Warehouse runs in your cloud. This is where your legal, security and procurement teams find the documents, the facts and the answers they need to review us.
Three facts before the documents.
Your data stays where it lives
Agents run on the enterprise AI platform you contract and TP Warehouse runs as a dedicated deployment in your cloud. In product operation your data does not pass through Supernomial systems, and we do not train models, on your data or anyone's.
How the data paths work→Agents act under your governance
What agents may do is set in policy your team approves and enforced in code. Every action lands in your audit trail under a named actor, and sensitive steps wait for your approval. Agents act under the governance you configure on your platform; the actions they take are your actions, and approval gates are yours to set.
What agents may do→Security you can review
Our controls are designed to meet the standards our clients are certified against: ISO 27001 internationally, SOC 2 in the United States. We have no certification and publish no audit report. For your review we answer your questionnaire, walk your security and data protection teams through each data path, and provide our policies under NDA.
For your security review→Supernomial Oy.
The entity behind every document on this site, and where to write.
| Item | Detail |
|---|---|
| Legal entity | Supernomial Oy |
| Business ID | 3542056-6 |
| Registered address | Bulevardi 21, 00180 Helsinki, Finland |
| Contact | hello@supernomial.co for everything: general and legal notices, privacy questions and data subject requests, the Data Processing Agreement and sub-processor notices, security questions, questionnaires, vulnerability reports, incident contact and support for customers' named contacts. The founders read it |
| Governing law and venue | The laws of Finland; exclusive jurisdiction of the District Court of Helsinki, subject to the arbitration election on the Order and to injunctive relief in any competent court (Terms of Service, section 15) |
Where each offering runs.
One table, no pictures: the data-path pictures and the short answers to standard vendor questions are on Data & Security.
| Offering | Where it runs | What reaches Supernomial | Your vendor relationship |
|---|---|---|---|
| Managed Agents | As a plugin on the enterprise AI platform you contract: Claude Cowork, Copilot Cowork, ChatGPT Work, Vibe Work or your in-house agentic AI | Nothing in product operation: as delivered the products contain no Supernomial endpoint, account, API key, license check or telemetry. Where the marketplace is a repository we publish, two kinds of read go to its host, not to us: the update fetch, and skills that read public reference files (country profiles, industry benchmarks) at the moment they are used. Each read is one-directional, carries no customer content, and is logged by the hosting provider under its own terms (requesting address, client software, time, requested file and any account the host requires); the file name shows the topic looked up, never your content, and we receive no record of who read what, at most aggregate traffic statistics | Your platform vendor under your Platform Agreement. Supernomial licenses the Materials under the Terms of Service and is neither controller nor processor in product operation |
| Private Agents | The same components on infrastructure you control outright: your own code repository and marketplace, your cloud, region, identity provider, network, logging and retention | Nothing in product operation; the reference-file reads described for Managed Agents apply unless the reference files are mirrored into your repository | Your cloud provider and platform vendor under your agreements with them; Supernomial under the Terms of Service, and under the Data Processing Agreement while our people build and maintain |
| TP Warehouse | One dedicated deployment: a managed database and sign-in platform in your own account plus the cloud platform we bring it up on with you, in the region you choose, both contracted by you; agents reach it over MCP from inside your environment | Nothing in product operation; model calls go to the model vendor you configure | Your cloud and database platform providers contract and bill the infrastructure to you; Supernomial licenses the software and implements and supports it, with access only as you authorize |
| AI Deployment Program and other services (implementation, support, restructures, workshops on your real data) | Inside your environment, with your team; our people work from Finland and Germany | What you share for the engagement: correspondence, and the working notes and deliverable drafts an engagement needs, on Supernomial-controlled laptops, deleted within 30 days of its end. We keep no standing access, no credentials and no other copies | Supernomial as your processor (or sub-processor where you act for your own clients) under the Data Processing Agreement and the Order |
| Academy (AI Accelerators, Live Workshops, Sponsored Presentations) | In person and online; registrations through this website | Registration data: event, name, company, work email, message. A workshop on your real data inside your environment is an engagement service | Supernomial as controller under the Privacy Policy; Academy terms in the Terms of Service, section 20 |
| Website (supernomial.co) | Vercel hosting; form records in Supabase; notification mail through Resend; our mail in Google Workspace | What you type into our forms, the hosting logs, and cookieless usage measurement, reported only as aggregates (Vercel Web Analytics). No cookies, no cross-site tracking | Supernomial as controller under the Privacy Policy; the vendors in List A below |
The documents.
Five documents, one set of facts: the same entity, contacts, timings and definitions on every page. A signable copy of the Data Processing Agreement or the Terms of Service is available on request at hello@supernomial.co.
Privacy Policy
What we collect on supernomial.co, in our forms, at events and in business relations, why, for how long, and your rights.
Data Processing Agreement
The processor terms, accepted with every Order, for the cases where we process personal data on your behalf during engagement work.
Security Notice
How security works in our delivery model, what we ship into your environment, how our people work inside it, incident handling and vulnerability disclosure.
Terms of Service
The contract terms for Managed Agents, Private Agents, TP Warehouse, the AI Deployment Program and Academy, the role split with your platform vendor and your cloud, and the terms for using this website.
Imprint
Provider identification for the German market (Impressum) and under Finnish law: entity, representative, registers, VAT ID, responsible person.
Sub-processors and vendors.
Three lists: product operation (none), our website and operations vendors (List A), and engagement sub-processors (List B).
Product operation: none. In product operation of Managed Agents, Private Agents and TP Warehouse no vendor of ours processes your data on our behalf, because it does not reach us, and no Supernomial sub-processor joins your vendor list. Your AI platform vendor and your cloud provider are your processors under your agreements with them, not ours.
List A: website and operations vendors. These providers run our website and company systems; those that process website visitor and contact data do so for Supernomial as controller, and the identity providers act as independent controllers for the sign-in step. None of them receives customer product data.
| Vendor | Purpose | Location | Safeguard |
|---|---|---|---|
| Vercel Inc. | Hosting, content delivery, the serverless functions behind our forms, hosting logs, cookieless web analytics | United States; worldwide content network; our form functions run in the EU | EU-US Data Privacy Framework (DPF) and Standard Contractual Clauses (SCCs) |
| Supabase Pte. Ltd | The database that stores contact requests and newsletter sign-ups | European Union (Ireland) | SCCs |
| Resend (operated by Plus Five Five, Inc.) | Notification emails from welcome.supernomial.co when you send a form or reserve a seat; sending logs kept for 30 days | United States | DPF and SCCs |
| Google Workspace (Google) | Our company email and collaboration suite, where form notifications and correspondence land | Google's data centers in the EU and the United States (Google Cloud EMEA Limited, Ireland, is our contracting entity) | DPF and SCCs |
| GitHub, Inc. | Source hosting for our website, the Materials we ship and the public reference files some skills read at runtime; it logs those fetches and reads under its own privacy statement; no customer content | United States | SCCs in GitHub's data protection agreement |
| Google LLC and Microsoft (Microsoft Corporation or Microsoft Ireland Operations Limited, depending on your account) | Identity providers for the customer portal sign-in once it is live; independent controllers for that step | United States (Google LLC, Microsoft Corporation); Ireland (Microsoft Ireland Operations Limited) | Their own notices apply to the sign-in step |
List B: engagement sub-processors. Where our people process personal data on your behalf during engagement work, the sub-processors are those in Annex III of the Data Processing Agreement: Google Workspace for engagement correspondence and deliverable drafts, and other tools only where your Order lists them. We give at least 30 days' notice of an addition or replacement, by email to the contact you name in the Order and by updating this list; you may object on reasonable data-protection grounds and, if no solution is found within 30 days, end the affected engagement services with a refund of prepaid fees for services not rendered.
Sub-processor lists last updated 22 August 2026. Changes are recorded in the change log at the end of this page.
Your AI inventory entry.
The fields a buyer pastes into its AI register. Copy them as they stand.
| Field | Entry |
|---|---|
| System description | Transfer pricing agent teams delivered as instruction, knowledge, playbook and workflow packages (the Expert Agent Harness) that run on your enterprise AI platform; and TP Warehouse, a data backend that agents operate over MCP inside your cloud |
| Provider of the AI system and model | Your enterprise AI platform vendor, under your Platform Agreement: Anthropic for Claude Cowork, Microsoft for Copilot Cowork, OpenAI for ChatGPT Work, Mistral AI for Vibe Work, or your own organization for in-house agentic AI |
| Deployer | Your organization |
| Supernomial's role | Supplier of the instruction, knowledge, playbook and workflow components and of implementation services. We do not operate the platform, the models or the cloud; in product operation nothing reaches us |
| Platforms | Claude Cowork, Copilot Cowork, ChatGPT Work, Vibe Work, in-house agentic AI; TP Warehouse on a managed database platform and a cloud of your choice, in your own accounts |
| Intended purpose | Transfer pricing work by qualified professionals, from documentation and operational transfer pricing to Pillar Two computations. Repurposing for a use the EU AI Act lists as high-risk is excluded by the Terms of Service, section 5.3 |
| Human oversight design | Agents draft, your people sign. Sensitive steps wait for your approval under the policies you configure; every action lands in your audit trail under a named actor; any agent can be halted at once |
| EU AI Act classification | Our agents are built for transfer pricing work by qualified professionals and are not intended for any use the EU AI Act lists as high-risk. The obligations for the underlying models sit with your AI platform. The transparency duties that apply since 2 August 2026 are met by design: agents are identified as agents, and their work passes your review before it leaves your organization. Our EU AI Act classification note is available on request |
| Data used | Inputs your users submit to your platform and the documents, data and TP Warehouse figures inside your environment, processed there under your Platform Agreement and your cloud agreement; reference content fetched read-only from public sources. No training on your data by Supernomial; nothing reaches Supernomial in product operation |
| Documentation on request | The EU AI Act classification note; an architecture walkthrough per offering; the plugin release for your review before installation. Write to hello@supernomial.co |
Questions procurement asks.
The answers we give in every security and legal review, written down once. Each answer is copied from the document that binds us.
Does our data leave our environment, and where is it processed?
No. Agents run on the enterprise AI platform you contract and TP Warehouse runs as a dedicated deployment in your cloud, in the region you choose. In product operation your data does not pass through Supernomial systems; model traffic runs under your agreement with your platform vendor.
During an engagement our people work inside your environment with identities you issue, for the time you set, under your terms. We keep no standing access and no credentials, and no copies of your data outside your environment beyond engagement correspondence and the working notes and deliverable drafts an engagement needs, which we delete within 30 days of its end under the Data Processing Agreement. Where we process personal data on your behalf, we do so in the EEA and, for engagements so scoped, inside your environment wherever you locate it; our people work from Finland and Germany.
Do you train models on our data?
No. We do not train models, on your data or anyone's. We do not train or fine-tune any model on Customer Content and do not permit anyone to do so on our behalf (Terms of Service, section 7.5). Nothing you author in your Customer Layer becomes training data through us.
The model vendor's own commitments on training sit in your Platform Agreement; check them at your platform's trust center, linked in the Security Notice.
Do you have a SOC 2 report or an ISO 27001 certificate?
No. Our controls are designed to meet the standards our clients are certified against: ISO 27001 internationally, SOC 2 in the United States. We have no certification and publish no audit report. For your review we answer your questionnaire, walk your security and data protection teams through each data path, and provide our policies under NDA.
We also have no third-party penetration test report of our own systems; you may test your TP Warehouse deployment in your own cloud under your rules. Your platform's and your cloud's certifications apply at the source: the Anthropic, Microsoft, OpenAI and Mistral AI trust centers are linked in the Security Notice.
Will you sign a DPA, and when does it apply?
Yes. Our Data Processing Agreement is accepted with every Order; no separate signature is needed, and a copy with a signature page is available on request at hello@supernomial.co. It applies whenever our people access your environment or receive your personal data in the course of engagement work: implementation, support, workshops on your real data and the AI Deployment Program. In product operation of Managed Agents, Private Agents and TP Warehouse nothing reaches us, and the DPA lies dormant.
Your AI platform vendor and your cloud provider process your data under your agreements with them; they are not our sub-processors. If your procurement process requires your own template, send it to hello@supernomial.co and we review it against ours.
Which sub-processors do you use?
None for product data: in product operation nothing reaches us, so no sub-processor touches it. For engagement work, Google Workspace carries engagement correspondence and deliverable drafts, and other tools only where your Order lists them (Data Processing Agreement, Annex III). For our website and company systems we use Vercel, Supabase, Resend, Google Workspace and GitHub, listed above with purpose, location and safeguard.
We give at least 30 days' notice of an addition or replacement, by email to the contact you name in the Order and by updating the list on this page.
How does the EU AI Act apply, and who is the provider?
Our agents are built for transfer pricing work by qualified professionals and are not intended for any use the EU AI Act lists as high-risk. The obligations for the underlying models sit with your AI platform. The transparency duties that apply since 2 August 2026 are met by design: agents are identified as agents, and their work passes your review before it leaves your organization. Our EU AI Act classification note is available on request.
The provider obligations for the models and the platform sit with your platform vendor under your Platform Agreement. We supply the instruction, knowledge and workflow components and implementation services, and we tell you if the intended purpose changes. If you repurpose the Materials for a use the Act lists as high-risk, you may become the provider of that system under Article 25 (Terms of Service, section 5.3). The AI inventory entry above gives the fields for your register.
What does the plugin do, how do we review it before install, and how do updates reach us?
What we ship is text your team can read: instruction files, knowledge, templates and workflows, kept in our code repository and delivered through the marketplace of your platform. The components of each release are listed in its release notes, and your administrators can review each release before installation. As delivered, the products contain no Supernomial endpoint, account, API key, license check or telemetry, and no Supernomial service is called at runtime. Some skills read public reference files (country profiles, industry benchmarks) from a repository we publish, at the moment they are used; that read goes to the repository host, not to us, and carries the requested file name, the requesting address, client software and the time, never your content.
Updates arrive through the marketplace channel you configure; the fetch carries no customer content, and where your platform supports it your administrators pin the reviewed revision and its digest. Updates do not alter the permissions, connectors or approval gates configured in your environment, and any update that adds a connector or an action needing new permissions is described in the release notes and disabled until your administrator enables it. We cannot and do not remotely disable software running in your environment.
Internet access: reference content is fetched read-only from public sources, web research runs only when a user asks for it, and access to your own systems goes through the connectors you approve on your platform. Where a deliverable is rendered to PDF and no LaTeX installation is found, the rendering script installs an open-source TeX distribution from its public mirror on first use; your administrators can pre-install it instead. No connection to any Supernomial system.
How is TP Warehouse secured in our cloud, and who keeps the keys?
One deployment per customer: a managed database and sign-in platform in your own account plus the cloud platform we bring it up on with you, in the region you choose; no shared tenancy; both contracted by you. Agents reach it over MCP from inside your environment, and model calls go to the model vendor you configure. The baseline we implement with your team: TLS in transit; encryption at rest by the platforms you contract; sign-in through the deployment's identity service, with single sign-on through your identity provider where you configure it; least-privilege access for agents and people, enforced at the database; private networking where your policy asks for it and the platform supports it; an audit trail of who changed what and when; backups under your platforms' settings.
You keep the administrator roles, the infrastructure is contracted and billed to you, and we access the instance only as you authorize for implementation and support. TP Warehouse is delivered with an open-source notice file and a component list.
Which AI tools do your people use with our material?
Inside your environment, the AI platform you contract. Outside it, no customer personal data goes into AI tools other than your environment or a tool named in your Order under terms that exclude training and fix retention (Data Processing Agreement, Annex II, item 5).
We use AI tools in our own engineering. A person reviews every change before it ships, and a transfer pricing expert reviews changes to knowledge and playbooks before release.
How do you handle security incidents?
hello@supernomial.co is the channel, and the founders monitor it. We log, triage, contain and fix. If a security incident affects personal data we process on your behalf or a deliverable we shipped to you, we notify your named contact without undue delay, and in any event within 48 hours after becoming aware. The first notice may be partial and is completed as facts develop; a written post-incident summary follows; we make no public statement naming you without your consent, unless the law requires it.
Where we act as your processor, notice is timed so you can meet your own deadline under Article 33 GDPR. If a defect in shipped content could cause harmful agent behavior, we issue an advisory and a patched release.
How do we run a security review of Supernomial?
Send your questionnaire (SIG, CAIQ or your own) to hello@supernomial.co; first response within 5 business days. We answer it and sit with your security and data protection teams until every question is closed. We provide an architecture walkthrough per offering, the Security Notice and Data & Security, the plugin release for your review before installation, our policies under NDA, and, for attachment to an Order, a copy of the security commitments in the Terms of Service and the Data Processing Agreement (Annex II).
Where documentation is not sufficient, you or an independent auditor may audit our compliance with the Data Processing Agreement at most once in any 12 months, on 30 days' written notice, within an agreed scope and at your cost (Data Processing Agreement, section 11).
What happens when the contract ends, or if Supernomial disappears?
Your agents and your warehouse keep running if our systems are down: they run on your platform and your cloud, and every engagement ends with documentation written so the system works without us. We cannot and do not remotely disable software running in your environment.
On termination the Customer Layer, Customer Data and Outputs stay with you in the formats they exist in; you may export them at any time, the Customer Layer as readable text (Terms of Service, section 7.6). The Managed Agents license ends with the fee and you uninstall the plugin within 30 days. For Private Agents and TP Warehouse, after at least 12 months of paid license you keep a license to the last delivered version without updates or support. We delete your confidential information in our possession within 30 days unless law requires retention, and transition assistance is available at the Order's rates for up to 90 days (Terms of Service, section 14).
Where are you based, and which law applies?
Supernomial Oy, Business ID 3542056-6, Bulevardi 21, 00180 Helsinki, Finland. Our people work from Finland and Germany. Our services are offered to businesses, public bodies and professional firms acting in their trade or profession, not to consumers.
Our agreements are governed by the laws of Finland, excluding its conflict-of-law rules and the CISG; the District Court of Helsinki has exclusive jurisdiction, subject to the arbitration election on the Order and to injunctive relief in any competent court. Customers outside the EEA and Switzerland may elect arbitration under the Arbitration Rules of the Finland Chamber of Commerce (the Finland Arbitration Institute), seat Helsinki, in English (Terms of Service, section 15).
Request a security review.
How a review runs, what we return, and what we cannot provide today.
Send your questionnaire (SIG, CAIQ or your own) to hello@supernomial.co; first response within 5 business days. We answer it and sit with your security and data protection teams until every question is closed.
- Where to send it: hello@supernomial.co, in any format.
- First response: within 5 business days.
- What we return: the completed questionnaire; an architecture walkthrough per offering; the Security Notice and Data & Security; the plugin release for your review before installation; our policies under NDA; and, for attachment to an Order, a copy of the security commitments in the Terms of Service and the Data Processing Agreement (Annex II), available on request at hello@supernomial.co.
- What we cannot provide today: a SOC 2 report, an ISO 27001 certificate, or a third-party penetration test report of our own systems. You may test your TP Warehouse deployment in your own cloud under your rules.
- To report a vulnerability: write to hello@supernomial.co. Scope, rules, safe harbor and response targets are in the Security Notice, section 11.
Changes.
One line per revision across the set.
- 22 August 2026: Trust Center published; documents version 1.0 (Privacy Policy, Data Processing Agreement, Security Notice, Terms of Service, Imprint).