Security & Governance
Built for the security review, not around it.
Regulated IT buyers do not adopt automation that cannot survive a security review. Ours is designed for it. Here is how the system handles access, data, and accountability.
Read-only-first access
Least privilege by default. We request read-only access wherever the workflow allows, and write access only where you explicitly approve it, scoped to named actions.
Credential handling
Credentials live in your secret manager. We do not store plaintext secrets, and access is revocable and tested before go-live.
PII and PHI handling
Data minimization by default. Agents work with the least data a task needs, and we never use your data to train models.
Human approval gates
Nothing client-facing ships without a human sign-off. Approval is a required step in the pipeline, not an optional setting.
Full audit logs
Every agent action is logged with a timestamp and a source reference, so any output can be traced back to its inputs.
QA verification layer
A separate reviewer agent verifies every claim against source data before any human sees a draft.
Model routing and providers
Work is routed across model tiers, and provider choices respect your AI usage policy and any DPA or BAA requirements.
Tenant isolation
For enterprise engagements, agents can run inside your tenant, scoped to your environment.
Subprocessors
The current list of subprocessors is provided on request and named in your Statement of Work.
Compliance posture
Built for SOC 2, HIPAA, SOX, and CMMC review, and we complete your vendor security questionnaire during onboarding. We state posture, not certifications we do not hold.
What we store, and what we do not
We store
- Engagement configuration and the prompt and workflow definitions you own
- Action logs with timestamps and source references
- The historical artifacts you share for calibration, for as long as the engagement needs them
We do not store
- Plaintext credentials or secrets
- Bulk copies of your source systems' data
- Anything used to train a model
This page describes how the system is built to operate. Specific controls are confirmed per engagement in your Statement of Work and security review. Posture statements are not claims of held certifications.
Stop producing reports. Start approving them.
Book a 30-minute consultation. We will map your highest-value automation opportunities, and you leave with next steps either way.