Security & data residency
Org-admin
These policies are set by organization admins and apply to everyone in the organization.

Data protection & model routing
This is your organization's most important data-protection control. It sets how strictly every member is pinned to EU data processing — across chat, the workflow assistant, agents, and workflows — by governing which models and routing paths may be used. Choose one of three levels:
| Setting | What it allows | Choose when |
|---|---|---|
| Strict EU (recommended · default) | Only models processed and routed directly to EU endpoints (or self-hosted). No brokers, no non-EU regions. | You require EU data residency — the safe, secure-by-default choice. |
| EU models | EU-processed models, but routing may go through an EU-pinned broker (e.g. OpenRouter restricted to EU-only upstreams) to widen model availability while keeping inference in the EU. | You want broader EU model choice and accept EU-pinned brokering. |
| All models | Any model and region, including non-EU providers. This opens niil to non-EU data processing. | You have deliberately decided non-EU processing is acceptable for your use case. |
- Strict EU is the recommended setting, and it is the default — niil is secure by default.
- The policy is decided by routing — where the request is actually sent — not just a model's label. A model is only offered if its routing satisfies your policy; under Strict EU and EU models, non-EU models are hidden from the picker and blocked for agents and workflows.
- Moving to All models is a deliberate org-admin decision to allow non-EU processing. Nothing leaves the EU unless you choose this level.
The full behaviour is described in EU sovereignty & residency.
Login MFA (email one-time code)
Require a 6-digit email code after the password on every password login. It is on by default. Members who sign in with a passkey or social provider already have strong authentication and aren't additionally prompted — see MFA & passkeys.
Why these are org-wide
Both are organization policies rather than personal preferences, so a single admin decision applies consistently to the whole team — the essence of niil's "secure by default" posture.