BottleCap AITrust Center

Overview

About BottleCap AI BottleCap AI builds efficiency-first foundational AI, developed entirely through in-house research in Europe. Our product family spans the full AI lifecycle: ThinkingCap, our fine-tuned language model that delivers the same quality with 50% fewer thinking tokens; AI Scan, our model evaluation and benchmarking tool; Pulse, a consumer news application powered by our proprietary CAP1 foundational model; and Enterprise Solutions for AI risk management, including real-time monitoring, security assessments, and compliance support for the EU AI Act and DORA. Everything we ship is built on a single conviction — that world-class AI can be developed responsibly, efficiently, and on European soil. Why Security and Trust Matter to Us Our customers entrust us with something extraordinary: the data, models, and decisions that power their businesses. As a European AI company, data sovereignty and regulatory alignment aren't features we bolt on — they are the foundation we build from. We help enterprises navigate the EU AI Act and DORA, which means we hold ourselves to the same standards we help our customers meet. Security and trust are not obstacles to innovation; they are what make innovation adoptable at scale. Our Commitment At BottleCap AI, we believe that trust is the foundation of innovation. Our commitment to security, privacy, and transparency is at the core of everything we build. This Trust Center provides real-time visibility into our security posture, including our progress toward SOC 2, ISO 27001, and ISO 42001 certifications. We employ industry-leading encryption, rigorous access controls, and continuous monitoring to ensure your data remains protected and compliant with global standards.

Compliance

Compliance frameworks BottleCap AI currently meets or is working toward to uphold their security and privacy commitments.

SOC 2
Compliant
ISO 27001
In progress
ISO 42001
In progress

Resource library

Our security, compliance, and policy documentation, including audit reports.

Incident Response Plan and Policy
Information Security PolicyMay 12, 2026
Software Development PolicyMay 18, 2026
Vendor Risk Management PolicyMay 18, 2026
Privacy PolicyMay 18, 2026
Business Continuity and Disaster Recovery PolicyMay 12, 2026
Code of ConductMay 12, 2026
SOC 2 Type 2 ReportJuly 23, 2026

Controls

Our security program is built on a complete set of controls that govern how we safeguard data and manage risk.

Infrastructure security
  • Vulnerability Management
  • Vendor Inventory
  • Cloud Security Posture Management
Organizational security
  • Security Operations Policy
  • Software Development Policy
  • Vendor Risk Management Policy
Product security
  • Security and Privacy Support
  • Encryption Management
  • Encryption Controls
Internal security procedures
  • Access Review
  • Endpoint Protection
  • Incident Response Plan
Data and privacy
  • Privacy Policy
  • Public Privacy Policy
  • Data Subject Request Inbox

Subprocessors

Trusted third parties that support our services and may process customer data as part of their function.

Google Vertex AI
No location specified
Claude
No location specified
Cloudflare
No location specified
GCP
No location specified
Stripe
No location specified
Powered by