ISMS Copilot
ISMS Copilot

Client audit work on AI that keeps nothing

Yes. The isms-fast-eu and isms-thinking-eu aliases on api.ismscopilot.com process every request on Mistral's EU-bound inference host, with no transfer of AI-model processing outside the EEA, zero retention of request content, and no training. Same price as the global path, from an OpenAI-compatible endpoint your scripts already speak.

The question a raw US model key cannot answer

A consultant running ISO 27001 engagements through a raw Anthropic or OpenAI key is doing something no client contract says out loud: every policy draft, risk register entry, and piece of audit evidence pasted into that key leaves the EEA and, on the default routing, lands on US infrastructure, where the provider's standard commercial terms keep inputs and outputs for up to 30 days. Regional-processing arrangements exist at both providers, but they are negotiated per account; a standard self-serve key does not have one. That is a transfer you must evaluate under ISO 27001 control A.5.14 and justify under GDPR Chapter V, with a DPA, a transfer impact assessment, and a sub-processor list your client's security team can read. None of that is a reason to give up AI on audit work. It is a reason to stop routing client evidence through a key that makes the transfer the default.

Why EU data sovereignty matters →

What changes with the EU aliases

Endpoint
https://api.ismscopilot.com/v1/chat/completions
EU aliases
isms-fast-eu, isms-thinking-eu
Processing
Mistral's EU-bound inference host. No transfer of AI-model processing outside the EEA. Storage sits in the EU (Frankfurt).
Retention
Zero retention of request content. No training on your prompts or outputs. Usage metadata is kept for billing only.
Proof per response
x-isms-processing-region: eu response header
Price
$2.80 in / $8.80 out per million tokens, same as the global path. Prepaid credits from $20, per-key spend caps.
Compatibility
OpenAI-compatible chat completions. OpenAI-protocol scripts change the base URL and the model name; raw Anthropic Messages clients swap in an OpenAI-compatible client.

Your first EU-processed request

curl https://api.ismscopilot.com/v1/chat/completions \
  -H "Authorization: Bearer sk-isms-..." \
  -H "Content-Type: application/json" \
  -d '{
    "model": "isms-thinking-eu",
    "messages": [{ "role": "user", "content": "Draft the A.5.14 information transfer policy for a 40-person SaaS company." }],
    "ismscopilot": { "frameworks": ["ISO_27001"] }
  }'

The response carries x-isms-processing-region: eu and names the framework modules injected into the answer.

The specialist part you were missing anyway

Swapping the region is the smaller win. The bigger one is what the endpoint knows before you send anything: curated framework modules, 100+ of them from ISO 27001 and SOC 2 to NIS 2, DORA, and the EU AI Act, injected at inference so you are not licensing and maintaining a standards corpus yourself. Pin up to eight modules per request, and every response discloses which ones it used. The catalog is public and dated, so a client can see what the model knows and how fresh it is. This is knowledge as the included part, not a prompt you hand-write and let go stale.

How framework knowledge injection works →

The math against a frontier key

List rates observed 2026-08-26: Claude Opus at $5.00 in / $25.00 out per million tokens on Anthropic's pricing page; isms-thinking-eu at $2.80 in / $8.80 out on ours. On compliance work that reads far more than it writes, that difference compounds across every engagement in the portfolio, and the EU path carries no premium over our global path. Two honest footnotes. Anthropic's prompt caching and batch pricing are real mitigations and belong in your math if your workload fits them. And we claim no quality superiority over Opus or any frontier model: the recorded head-to-head, Claude Code alone against Claude Code delegating to ISMS Copilot, was a pre-registered accuracy tie on the tested items. The case for switching is region, retention, included knowledge, and price. Not a quality trophy.

Full pricing math and evidence →

Prefer to stay inside Claude?

Many consultants do their real work inside Claude or ChatGPT, not in scripts. For that shape there is a second door: the Account MCP connector. Your agent calls create_conversation and send_message against your ISMS Copilot account, and with Advanced Data Protection enabled in the web app, all AI processing routes to Mistral with zero retention, on every plan including Plus at $20 a month. Usage rides your chat subscription, not a prepaid wallet. The ADP toggle lives in the web app, so set it once per account; workspaces created over the connector do not inherit it automatically.

Connect any MCP client →

Sources and product truth

What this page is not claiming

EU processing is a routing choice you make per request, not a company-wide hosting claim: the global aliases (isms-fast, isms-thinking, isms-mini) process in the United States, and we disclose that the same way we disclose the EU path. The endpoint is text in, text out: no tool calling, no JSON mode, no multimodal input; streaming is supported. There is no bring-your-own-key option; the key is ours and the spend cap is per key. And the output is compliance guidance, not an audit opinion: the consultant signs the deliverable, exactly as before.

Frequently Asked Questions

Is ISMS Copilot hosted in the EU?

Storage and hosting sit in the EU (Frankfurt), and the isms-fast-eu and isms-thinking-eu aliases process AI-model calls on Mistral's EU-bound inference host with no transfer of AI-model processing outside the EEA. The global aliases process in the United States. We do not claim a product-wide EU-hosted label; region is a per-request routing choice you control.

Is client data used for training?

No. On the Model API, request content is not stored and is never used for training; usage metadata is retained for billing. On the -eu aliases this runs under a zero-retention agreement with Mistral.

Do I have to rewrite my scripts to switch from Anthropic?

If your scripts already speak the OpenAI chat completions protocol, you change the base URL, the Authorization header, and the model name. A raw Anthropic Messages API client is a different wire protocol: swap in an OpenAI-compatible client, or call the endpoint with plain HTTPS. One real limit: the API rejects tool/function definitions, so tool-calling agents need the sub-agent step pattern or the Account MCP connector instead.

How do I prove the processing region to a client?

Three ways: the x-isms-processing-region: eu header on every response, the API sub-processor list on the trust center naming Mistral's EU-bound inference host, and the zero-data retention documentation. A client can verify the region from the response itself, not from your assertion.

What does it cost for a solo consultant?

Prepaid credits from $20, pay-as-you-go at $2.80 in / $8.80 out per million tokens on the -eu aliases, per-key spend caps so an unattended loop cannot burn the balance. If you work inside Claude instead, the Account MCP rides a chat plan from $20 a month. Live rates live in the console; the console wins when prices change.

What about the web app?

The chat product has Advanced Data Protection: a setting in the web app, on every plan, that routes all AI processing to Mistral with zero retention, bypassing the default routing path. Web search fails closed under it. Set it once per account; it applies to chat, and workspaces you create over the MCP connector do not inherit it automatically.

Take client evidence off the US key

Create an sk-isms key, point your existing scripts at the -eu aliases, and set a spend cap. EU processing and zero retention apply when you use isms-fast-eu and isms-thinking-eu; the global aliases process in the United States.