What the tool does

General AI tools like ChatGPT invent process names and confuse capability levels. ASPICE Pro does not. Its knowledge base is verified expert content, reviewed by a person. Every answer gives a source reference with document and page, so you can check it yourself. The knowledge is held as a knowledge graph, built on Automotive SPICE® and the Automotive SPICE® Cybersecurity Extension. Hosted in Germany.

A language model predicts plausible text, not true text. When it lacks a fact, the same mechanism that writes correct answers writes confident wrong ones. Nobody eliminates that, and any vendor claiming they have is misleading you. ASPICE Pro constrains it: answers are grounded in a curated, human-verified knowledge base rather than the model's general recall, and every claim carries a citation to book and page that you can open. An answer that cannot point to a source is visible as such.

Yes. Ask in German and you get German; the same for other languages. An assistant can also be set to always answer in a fixed language. Source excerpts stay in the language of the original document, because a quoted clause should read as it does in the standard.

Compliance & security

Neither is held today, and we will not imply otherwise. What exists is a documented security posture mapped control-area by control-area to the VDA ISA catalogue, so we answer your security questionnaire directly, with gaps named rather than glossed. Physical and infrastructure security is ISO/IEC 27001-certified through our provider (Hetzner, Germany). If TISAX is a contractual condition for you, say so and it becomes a scoped commitment with a timeline.

Everything persistent is stored in Germany on Hetzner infrastructure: application, databases, knowledge graph, backups. Model inference runs transiently on an EU endpoint (Google Vertex Europe, via OpenRouter). Vercel serves static frontend assets only. Stripe handles billing and never sees content. No sub-processor outside the EU/EEA stores content at rest. Records of processing, technical and organisational measures, and a per-sub-processor transfer assessment are available for review.

No training, no retention, inference stays in Europe. Inference is pinned to an EU endpoint under a zero-data-retention policy, enforced per request in code, and it fails closed: if the EU endpoint is unavailable the request fails rather than routing elsewhere. Nothing is stored outside Germany. Embeddings are computed once and stored on our own infrastructure.

Yes. Melster Consulting GmbH is the provider and acts as your processor under Art. 28 GDPR. We conclude a data processing agreement with you as part of the engagement. Behind it: records of processing (Art. 30), technical and organisational measures (Art. 32), a per-sub-processor third-country transfer assessment, a documented breach-notification process, and data-subject rights including export and deletion. If your legal team wants to review specific clauses, that conversation is welcome.

Yes. NIS2 does not apply to us directly at our size. It only reaches us through you: if NIS2 applies to you, it requires you to check your suppliers' security (Art. 21(2)(d)), so you send us a questionnaire. We complete that questionnaire from our documented security posture, the same VDA ISA control-area mapping and measures described above. You get specific answers with named gaps, not a brochure.

Your data in ASPICE Pro is your working sessions and your account. Automated daily backups run on German infrastructure with tiered retention. For a dedicated deployment, continuity arrangements such as off-site backup targets and restore objectives go into the contract, sized to your requirements.

Yes. Your account and personal data can be exported in a structured, machine-readable format, and deleted, under GDPR Arts. 15, 17 and 20. No fees.

Deployment & data isolation

Yes, in layers. In the shared platform, your account's data is scoped to your account with no cross-account path, and team plans have role-based access. A dedicated single-tenant instance is available on request: your own data stores, your own domain, in your jurisdiction. The model endpoint is configurable, which is usually what decides things (see next).

Yes, and it is the cleanest answer to any data-residency concern. All model access goes through one abstraction speaking the OpenAI-compatible protocol against a configurable endpoint: your own cloud deployment, an EU-region deployment you control, or a self-hosted model inside your network. In that configuration prompt content never leaves your infrastructure, and there is no fallback path to an external provider. This is a configuration, not a development project, and it pairs with a dedicated instance.

Integrations & extensibility

Yes. The platform exposes an OpenAI-compatible API, so any system that can call an OpenAI-style endpoint, TRACE included, can consume ASPICE Pro answers. Co-development on request.

Yes, on request. Custom functionality is built as a scoped project, not switched on in the existing tool. Your example, code maturity analysis, is a big one: analysing source code is a different kind of work than the tool does today, so it is a real development effort, not a small add-on. We scope it with you and are honest about the size before you commit. Co-development on request.