Security

Control is the architecture, not a checkbox.

AI that can act on real systems is only acceptable if its limits are real. This page describes how those limits work — data control, permissions, approvals, model governance, isolation, auditability, integration control and deployment.

Start free trialSee the controls
The stance

We would rather state limits than claim maturity.

Every control below is something the platform does. The operator holds ISO 27001 and ISO 9001 certification, data processing terms are available on request, and hosting is in the EU by default. Ask for the documentation your review needs and we will tell you exactly what exists today.

What we claim
Product behaviour: how data flows, how permissions are enforced, where approvals sit, what is logged, and where it can be deployed. Plus the operator’s ISO 27001 and ISO 9001 certification and EU data residency.
What we do not claim
We do not present the operator’s certification as a statement about every part of this platform, and we do not claim SOC 2 or any audit report we cannot hand you. Ask and we will tell you exactly what the certified scope covers.
Request the security pack
Certifications and residency
Held by the operator of the platform
ISO 27001
Certified information security management system. Certificate and scope statement available on request.
ISO 9001
Certified quality management system, covering how the service is delivered and supported.
GDPR
Data processing terms and sub-processor information available on request.
EU data residency
Hosted in the EU by default. Private cloud and fully on-premise deployment available.
We deliberately do not claim SOC 2 or any audit report we cannot provide, and we do not present a certification as covering more of the platform than its certified scope. Ask for the scope statement and you will get it.
The controls

Eight areas your security team will ask about.

01Where your data goes, what is kept and for how long.

Data control

·Content is inspected against your rules before it can leave the network.
·Retention is configurable per workspace, thread and audit record.
·Export and deletion are available on request, with a record of both.
·Provider accounts stay yours — model traffic runs on your own contracts.
02Who may do what, enforced rather than documented.

Access and permissions

·Single sign-on with your identity provider, and role-based access inside.
·People, applications and agents each hold their own credentials and scopes.
·Permissions are inherited downward and cannot be widened locally.
·Access reviews are supported by a queryable record of who reached what.
03The places where a person must sign.

Human approval points

·Writing to a system of record can require a named approver.
·Anything sent outside the organisation can be gated the same way.
·Spend above a threshold stops and waits for a decision.
·Approval requirements live in the workflow definition, not in a preference.
04Which models are allowed, for which work.

Model governance

·An approved model catalogue per team; unapproved models are unavailable.
·Routing rules by task, sensitivity, quality and cost.
·Self-hosted and on-premise models can be the only permitted option.
·Provider changes are made centrally, without touching applications.
05One organisation cannot reach another.

Workspace isolation

·Tenant-level separation of workspaces, context and history.
·Thread-scoped context: an agent reads what the thread allows, not everything.
·Environment separation for evaluation, staging and production use.
·No cross-tenant training or reuse of your content.
06The record that answers the question later.

Auditability

·Every request, model, decision, approval and cost is attributable.
·Queryable by user, team, application, workflow and time range.
·Configurable retention with export for compliance review.
·Run history for workflows, including inputs and outcomes.
07Connected systems stay under control.

Integration controls

·Scoped credentials per integration, narrowest permissions that work.
·Read and write granted separately, and per workflow.
·One-place revocation that stops everything depending on it.
·Every call to a connected system is logged.
08Where the platform itself runs.

Deployment and processing

·EU cloud by default.
·Private cloud deployment for organisations that require it.
·Fully on-premise deployment, including your own models.
·Data processing terms and sub-processor information available on request.

Bring your security team into the evaluation early.

The controls above are the whole conversation. If something is missing for your review, we would rather hear it now than at procurement.

14 days · no payment card · bring your own provider account