AI Policy

AI Policy

How Nethemba uses artificial intelligence

We use the most capable commercially available AI models to increase the quality, depth, speed and coverage of our security services. This page explains transparently which AI providers we work with, what data may be shared with them and what that means for confidentiality.

Why we use AI

Nethemba uses generative artificial intelligence tools based on large language models (“AI tools”) in the delivery of its security services, including penetration testing, security audits and related consulting. We use the most capable commercially available models (e.g. Anthropic’s Claude Fable and Claude Opus model families, OpenAI’s GPT model families, and comparable models of other providers), because they measurably increase the quality, depth, speed and coverage of our work.

Which AI providers we use

AI tools are operated by third parties (“AI providers”). In connection with the provision of our services, information may be disclosed to the following AI providers and their affiliates:

Anthropic, PBCUSA, incl. Anthropic Ireland, Limited — Claude, Claude Code
OpenAI, Inc. / OpenAI, L.L.C.USA, incl. OpenAI Ireland Ltd — ChatGPT, Codex, GPT API
Google LLC / Google Ireland LtdGemini, Vertex AI
Microsoft Corp. / Microsoft IrelandAzure OpenAI Service, GitHub Copilot
xAI Corp.USA — Grok
Mistral AI SASFrance — Le Chat, La Plateforme
Cloud infrastructureAmazon Web Services, Google Cloud, Microsoft Azure — hosting of the above models

For a specific engagement, this list may be narrowed or extended only as agreed with the customer in the contract.

What data may be shared with AI providers

During an engagement, the following categories of information relating to the customer and the tested systems may be transmitted to and processed by AI providers:

  • identification and configuration data of tested systems (IP addresses, URLs, domain names, software versions and settings),
  • the content of network communication with tested systems (e.g. HTTP requests and responses),
  • source code or parts thereof, if supplied by the customer,
  • logs and related data,
  • information on identified vulnerabilities, including the manner of their possible exploitation,
  • parts or the entirety of the final report,
  • other technical or business information necessary for the proper provision of the services.

The transmitted information may also include personal data contained in the tested systems or in communication with them.

Our safeguards

  • We use AI tools in paid, business or API versions under which the AI provider contractually undertakes not to use inputs and outputs for training of its models, where such a version is available.
  • Where offered by the AI provider, we use zero data retention or reduced retention modes, under which the AI provider does not persistently store inputs and outputs after processing.
  • We make reasonable efforts not to disclose credentials (passwords, API keys, tokens) to AI tools in usable form and to minimise the scope of personal data disclosed.
  • Upon written request, we will inform the customer which AI tools were used in the provision of the services.

What this means for confidentiality (NDA)

The processing of information by AI providers is governed by their own contractual terms and security measures, over which we have no control. AI providers may temporarily retain information (e.g. for abuse prevention) and process it on servers outside the EU/EEA, in particular in the USA. For this reason, to the extent information is disclosed to AI providers, we cannot guarantee its confidentiality, and our contracts contain an explicit AI clause under which such disclosure is not a breach of any confidentiality obligation or NDA. Customers who require a strict NDA without any AI processing can request our standard (non-AI) contract version; scope, timeline and pricing may differ.

Personal data (GDPR)

Where personal data are processed on behalf of the customer, AI providers act as our sub-processors within the meaning of Art. 28(2) GDPR. Details are regulated in our Data Processing Agreement (DPA), which lists AI providers as sub-processors. Transfers of personal data to third countries are covered by appropriate safeguards within the meaning of Chapter V GDPR (e.g. the EU-U.S. Data Privacy Framework or standard contractual clauses).

Download DPA (PDF, English)

Also available in: SK · CS · DE · ES

Changes to this policy

We keep this page up to date. For a specific engagement, the list of AI providers agreed in the contract prevails, and its extension requires the customer’s prior consent. Questions: info@nethemba.com.

Last updated: 27 July 2026