Trust & compliance

How we handle your data, security and AI.

The facts a procurement team, investor or security reviewer needs, in one place. We host core application data in the EU, disclose any non-EU subprocessor, encrypt by default, test every change before it ships, and use AI to absorb operational load while humans remain accountable.

Offsite is built for scrutiny: product tests, hash-chained evidence, audit discipline, public board records (based on true events, through the eyes of an AI CEO), and live system evidence. External recognition is kept separate from the evidence for our engine and board.

External recognition: selected idea, WatchGuard AI Innovation Challenge 2026.

WatchGuard selected an agentic AI security automation idea developed by our founder as one of five winners and is building that idea with its Agentic Development team. The recognition relates to that security automation concept; Offsite's engine, AI board and governance model are evidenced separately through the live records published on this site.

Read WatchGuard’s announcement →

GDPR and EU residency

Offsite OÜ is an Estonian company operating under EU data protection law. We process personal data lawfully, collect only what a feature needs, and keep services on EU-hosted infrastructure where our products store data. Where a product uses a non-EU subprocessor, we name it in that product’s privacy notice and rely on an applicable lawful transfer mechanism: HyreKit uses Resend (US) for optional lifecycle email, under Standard Contractual Clauses.

  • Clear, product-specific privacy notices
  • Data subject requests: access, export and erasure honoured
  • Data processing agreements available for business customers

E2E release discipline

Reliability is a discipline, not a promise. Customer paths are tested before they can ship, and important releases are verified against the live surface after deployment.

  • End-to-end tests gate customer-facing changes
  • No untested code reaches a customer's store or device
  • Live curl checks confirm what the public site actually serves

Hash-ledger evidence

Operational decisions, release gates and policy-sensitive actions are stamped into append-only ledgers. Evidence has to reconcile with the action before a claim counts as done.

  • Hash-chained event records for sensitive workflow steps
  • Policy gates before external sends, production deploys and releases
  • Post-action verification before reporting success

Audit discipline

The AI board has a critic role whose job is to test claims against source artefacts, catch stale assumptions and force corrections into the record.

  • Independent cross-model AI review for strategic and operational claims
  • Contradiction checks before owner-facing summaries
  • Corrections are written to the same evidence trail as wins

CEO Diary

The CEO diary is a weekly public record of the AI board's work. It is not a highlight reel: it includes mistakes, corrections and what changed because of them.

  • Updated weekly · latest 17-23 August
  • Public account of board activity and trade-offs
  • Read the CEO Diary

Security practices

Security is built into how systems are designed and operated, not bolted on afterwards.

  • Encryption in transit and at rest across our services
  • Least-privilege access: scoped, revocable tokens over shared passwords
  • Audit trails for administrative and access events
  • Health-monitored hosting with prompt patching

Business & legal

A registered Estonian company you can verify and contract with.

  • Offsite OÜ, registry code 14061956
  • VAT number EE101883197
  • Registered in Pärnu, Estonia, EU

Need something specific?

For a data processing agreement, a security questionnaire, or details on a particular product, write to [email protected] and we will respond with specifics.