Skip to content

Security & data residency

Org-admin

These policies are set by organization admins and apply to everyone in the organization.

The data-protection / model-routing policy (Strict EU, EU models, All models) in organization settings
Data protection & model routing

Data protection & model routing

This is your organization's most important data-protection control. It sets how strictly every member is pinned to EU data processing — across chat, the workflow assistant, agents, and workflows — by governing which models and routing paths may be used. Choose one of three levels:

SettingWhat it allowsChoose when
Strict EU (recommended · default)Only models processed and routed directly to EU endpoints (or self-hosted). No brokers, no non-EU regions.You require EU data residency — the safe, secure-by-default choice.
EU modelsEU-processed models, but routing may go through an EU-pinned broker (e.g. OpenRouter restricted to EU-only upstreams) to widen model availability while keeping inference in the EU.You want broader EU model choice and accept EU-pinned brokering.
All modelsAny model and region, including non-EU providers. This opens niil to non-EU data processing.You have deliberately decided non-EU processing is acceptable for your use case.
  • Strict EU is the recommended setting, and it is the default — niil is secure by default.
  • The policy is decided by routing — where the request is actually sent — not just a model's label. A model is only offered if its routing satisfies your policy; under Strict EU and EU models, non-EU models are hidden from the picker and blocked for agents and workflows.
  • Moving to All models is a deliberate org-admin decision to allow non-EU processing. Nothing leaves the EU unless you choose this level.

The full behaviour is described in EU sovereignty & residency.

Login MFA (email one-time code)

Require a 6-digit email code after the password on every password login. It is on by default. Members who sign in with a passkey or social provider already have strong authentication and aren't additionally prompted — see MFA & passkeys.

Why these are org-wide

Both are organization policies rather than personal preferences, so a single admin decision applies consistently to the whole team — the essence of niil's "secure by default" posture.