Home
Magazine
revel8 vs. Adaptive Security: DACH Platform or US Scale?
revel8 vs. Adaptive Security: DACH Platform or US Scale?

revel8 vs. Adaptive Security: DACH Platform or US Scale?

September 18, 2026
7 min read
Lana Kuzmina
Cyber Threat Analyst
lana

Comparing AI-native threat platforms Adaptive Security and revel8 reveals a stark choice: US scale versus DACH data sovereignty. This guide breaks down the compliance, threat focus, and legal realities of both platforms to help you choose the right fit.

Table of contents

Get started
with revel8

  • The US CLOUD Act and FISA 702 expose EU data hosted by US-headquartered vendors to extraterritorial access.
  • Adaptive Security has raised $146.5M for a broad US-focused platform, but does not publicly document EU data residency or default group anonymization.
  • Under KUG Sec. 22, generating deepfakes of employees without GDPR-compliant consent carries severe legal risk in Germany.
  • revel8 supports works council agreements by default with strict processing boundaries and a minimum group size of five.
  • A two-vendor strategy — Adaptive Security for US operations, revel8 for DACH entities — is a legitimate enterprise pattern.

Why does data sovereignty matter for AI threat simulations?

As generative AI accelerates the volume and realism of social engineering, enterprise security teams are re-evaluating how employee risk data is stored and processed. AI-driven threat platforms process sensitive internal telemetry, including target employee lists, organizational hierarchies, phone numbers, role descriptions, and individual interaction logs. When a corporate threat simulation provider operates under US corporate jurisdiction, European organizations face significant regulatory exposure under cross-border data transfer laws.

The core friction stems from the conflict between US surveillance statutes and European data protection law. Under Section 702 of the Foreign Intelligence Surveillance Act (FISA 702) and the Clarifying Lawful Overseas Use of Data Act (CLOUD Act, 18 U.S.C. § 2713), US federal authorities can compel any company subject to US jurisdiction to disclose data within its possession, custody, or control. Because legal control follows the corporate parent rather than physical server geography, hosting data in European cloud regions does not exempt a US-headquartered vendor from US court orders. This extraterritorial reach directly clashes with Article 48 of the EU General Data Protection Regulation (GDPR), which prohibits disclosures based on foreign judicial orders absent an international agreement.

  • Legal control test: US legal process reaches data within a provider's possession, custody, or control regardless of whether that data is stored inside or outside the United States.
  • Direct statutory conflict: Complying with a US CLOUD Act order forces a provider into a violation of GDPR Article 48.
  • Gag order constraints: US disclosure requests frequently include non-disclosure orders under 18 U.S.C. § 2705(b), preventing notice to European data subjects.

To navigate this legal exposure without sacrificing modern AI capabilities, multinational organizations increasingly adopt a two-vendor strategy. Under this model, US operations rely on domestic platforms tailored to North American regulatory norms, while European entities deploy sovereign platforms hosted on infrastructure like the STACKIT Marketplace to maintain strict compliance with EU standards.

How do sovereign DACH platforms and Adaptive Security approach AI-driven threats?

While legacy awareness tools relied on static template libraries and passive video modules, modern security platforms use artificial intelligence to emulate real-world attack vectors. However, Adaptive Security and sovereign European providers differ significantly in platform architecture, threat focus, and regional localization.

Adaptive Security, based in New York, has established significant scale in the North American market, raising $146.5 million to date, including an $81 million Series B led by Bain Capital Ventures with participation from NVentures, the OpenAI Startup Fund and Andreessen Horowitz. Its offering centers on a library of more than 1,000 training resources with an AI content creator, localized across dozens of languages with jurisdiction-specific compliance tracks. In contrast, specialized European platforms focus heavily on open-source intelligence (OSINT) profiling and continuous multi-channel execution across email, SMS, voice, and video.

Platform CapabilityAdaptive Securityrevel8 Platform
Headquarters & Legal JurisdictionUnited States (New York)Germany (Munich)
Cloud InfrastructureHosting regions not publicly documentedSovereign STACKIT Cloud in Germany
Total Capital Raised$146.5 millionEuropean Venture Capital
Simulation ChannelsMulti-channel, plus a separate cloud email security productContinuous Multi-Channel (Email, SMS, Voice, Video)
Reporting GranularityPer-person, team and group risk scoresDefault Group Anonymization (min. 5 users)
Target Market AlignmentUS Enterprise FocusDACH & EU Enterprise Focus

For organizations addressing multi-vector social engineering, channel coverage is a critical evaluation criterion. Synthetic voice cloning and vishing require regional voice models and local dialect nuance, which is a different question from how many languages a content library lists. The revel8 Platform natively integrates multi-channel simulations, using OSINT data to mirror real attack surfaces across European business contexts.

What does real EU AI Act compliance look like for deepfakes?

Deploying generative AI to simulate threats inside an enterprise introduces strict regulatory responsibilities under the European Union Artificial Intelligence Act (EU AI Act). Organizations cannot rely on generic vendor assurances or basic website privacy badges; deployers of AI systems face explicit statutory obligations designed to protect worker rights and data integrity.

Article 26 of the EU AI Act sets out the obligations of deployers of high-risk AI systems, from human oversight to log retention and worker information. Organizations using AI to generate simulated interactions must establish verifiable operational safeguards prior to putting systems into workplace service.

  1. Worker notification: Before putting a high-risk system into service at the workplace, employers must inform workers' representatives and the affected workers that they will be subject to it.
  2. Automatic log retention: Deployers must keep the logs the system automatically generates for a period appropriate to its purpose and at least six months.
  3. Human oversight protocols: Natural persons with the necessary competence, training and authority must be assigned to oversee the system, and use must be suspended where a risk is identified.
  4. Data Protection Impact Assessment (DPIA): Deployers must use the provider transparency information supplied under Article 13 to carry out their DPIA under GDPR Article 35.

Substantive compliance also requires verifiable local governance artifacts. European enterprises must execute a formal Data Processing Agreement (Auftragsverarbeitungsvertrag — AVV) governed by EU law, appoint a dedicated European Data Protection Officer (DPO), and ensure alignment with mandatory NIS2 requirements to satisfy statutory audit scrutiny.

Simulating advanced social engineering attacks often involves generating synthetic audio or video representations of company executives and staff. In the DACH region, synthesizing an individual's likeness without robust legal governance introduces significant corporate liability under personality rights legislation.

Section 22 of the German Artistic Copyright Act (Kunsturhebergesetz — KUG § 22) establishes that a person's likeness may only be distributed or publicly displayed with the consent of the person depicted. Creating deepfake avatars using unverified public tools or self-service features therefore creates immediate legal exposure if an employee's voice or likeness is cloned without documented, freely given consent that also satisfies GDPR standards for processing personal data.

To mitigate civil liability and regulatory fines, enterprise threat platforms must enforce strict deepfake governance. This includes role-based access controls for asset generation, clear synthetic watermarking, and mandatory deletion duties that remove personal training assets immediately upon campaign completion. Securing explicit consent ensures that realistic threat exercises build employee resilience without compromising individual privacy rights or triggering legal disputes over spear phishing simulations.

How does platform design impact your works council agreement?

In Germany, Austria, and Switzerland, rolling out any system that monitors employee behavior requires close coordination with worker representatives. Under Section 87 of the German Works Constitution Act (Betriebsverfassungsgesetz — BetrVG), the works council (Betriebsrat) possesses mandatory co-determination rights regarding technical devices intended to monitor employee conduct or performance.

Attempting to negotiate a works council agreement (Betriebsvereinbarung) with a platform designed primarily for US management oversight often leads to friction. Standard US management dashboards frequently aggregate individual failure metrics, exposing specific users to performance monitoring. In contrast, platforms designed for DACH compliance incorporate privacy-by-design safeguards directly into the database architecture.

  • Default group-level anonymization: Individual performance tracking is disabled by default, reporting data only in aggregate groups with a mandatory minimum threshold of five employees.
  • Pseudonymization by default: user identifiers are pseudonymized at the database layer, so managers see group results rather than named individuals. Pseudonymized data remains personal data under the GDPR and stays inside the customer tenant.
  • Strict tenant isolation: All data processing occurs exclusively within the customer's isolated cloud tenant, ensuring employee telemetry is never used to train global AI models.

By embedding default group anonymization into the core platform, security leaders can provide works councils with concrete legal guarantees. This structural approach accelerates Betriebsvereinbarung sign-offs while maintaining measurable risk metrics like the Human Firewall Index across the organization.

Which AI security platform is the right fit for your enterprise?

Selecting between Adaptive Security and sovereign European platforms depends on an organization's corporate structure, primary geographic exposure, and regulatory mandates. Both platforms offer advanced generative AI simulation capabilities, but they serve distinct operational profiles.

  • Adaptive Security is best suited to North American enterprises and purely US-headquartered multinationals requiring broad module catalogs, extensive vendor funding scale, and direct integration into US-centric tech stacks.
  • The revel8 Platform is best suited to DACH Mittelstand enterprises, DAX organizations, and European entities subject to NIS2, GDPR, and works council co-determination that require sovereign data residency on STACKIT in Germany and localized threat patterns.

For global enterprises managing diverse regional requirements, deploying a dual-vendor model offers a pragmatic solution. Using Adaptive Security across North American business units preserves US vendor alignment, while standardizing on sovereign platforms across European subsidiaries ensures full compliance with local labor laws and sovereign data protection standards during multi-channel security simulations.

If your security team is evaluating how to build measurable employee resilience against deepfakes and multi-channel social engineering without compromising European data sovereignty, we invite you to consult with our specialists to review our architectural benchmarks and works council documentation.

FAQ

What is the main difference between revel8 and Adaptive Security?

Adaptive Security is a US-headquartered platform backed by $146.5M in funding, with a library of more than 1,000 training resources and its own cloud email security product. In contrast, revel8 is an AI-native European platform hosted on STACKIT in Germany, specializing in OSINT-driven multi-channel simulations that comply with strict DACH works council and EU AI Act regulations.

Does Adaptive Security offer European data sovereignty?

Adaptive Security does not publicly document its hosting regions, and its US headquarters subjects it to the US CLOUD Act and FISA 702. This means US authorities can potentially compel access to data wherever it is stored, unlike revel8, which operates entirely within German jurisdiction on STACKIT.

How does KUG Sec. 22 affect deepfake simulations in Germany?

KUG Sec. 22 (Kunsturhebergesetz) mandates that images and likenesses of individuals may only be distributed with explicit consent. Using public, self-service deepfake tools without enterprise governance and explicit employee approval creates severe legal exposure for German companies.

Can we use both revel8 and Adaptive Security in a global enterprise?

Yes. A two-vendor strategy is a legitimate and common enterprise pattern. Organizations often deploy Adaptive Security for their US-headquartered workforce while leveraging revel8 for DACH and EU entities to support NIS2 alignment, works council approval, and GDPR compliance.

How does revel8 handle works council (Betriebsvereinbarung) requirements?

revel8 expedites works council negotiations by ensuring that reporting is anonymized by default at the group level, with a minimum group size of five. No individual performance data is visible to management, protecting employee privacy and preventing behavioral monitoring.

Sources

Related Articles

White abstract curved shape with jagged edges on a black background.

Ready to defend against
AI-powered attacks?