Designed with security principles in mind
We won't claim certifications we don't hold. Here's what's actually true about how the platform is built.
Human Approval Controls
Sensitive actions — sending a message, executing a trade, submitting client-facing work — pause for explicit human sign-off before they happen. Nothing external fires by default.
Audit Trails
Bot actions, task status changes and approval decisions are recorded, so activity can be traced after the fact rather than taken on faith.
Client Workspace Separation
Each client's documents, tasks and records are organised into their own workspace rather than pooled together.
Secure Vault Architecture
Client documents live in a dedicated storage layer with access-level controls, separate from general task data.
Controlled Bot Permissions
Bots operate within defined boundaries for their role — access is scoped to what the job requires, not granted broadly by default.
Local / Private Deployment Options
The platform can run against locally-hosted models and infrastructure rather than requiring every request to leave your environment.
Data Minimisation
We aim to collect and retain what's operationally necessary, not everything that could theoretically be useful someday.
Future Compliance Roadmap
We're continuing to build toward broader compliance and certification as the platform and its client base grow.
We do not claim full compliance with any specific regulatory framework unless we hold the certification to back it up.