SECURITY & TRUST

Designed with security principles in mind

We won't claim certifications we don't hold. Here's what's actually true about how the platform is built.

Human Approval Controls

Sensitive actions — sending a message, executing a trade, submitting client-facing work — pause for explicit human sign-off before they happen. Nothing external fires by default.

Audit Trails

Bot actions, task status changes and approval decisions are recorded, so activity can be traced after the fact rather than taken on faith.

Client Workspace Separation

Each client's documents, tasks and records are organised into their own workspace rather than pooled together.

Secure Vault Architecture

Client documents live in a dedicated storage layer with access-level controls, separate from general task data.

Controlled Bot Permissions

Bots operate within defined boundaries for their role — access is scoped to what the job requires, not granted broadly by default.

Local / Private Deployment Options

The platform can run against locally-hosted models and infrastructure rather than requiring every request to leave your environment.

Data Minimisation

We aim to collect and retain what's operationally necessary, not everything that could theoretically be useful someday.

Future Compliance Roadmap

We're continuing to build toward broader compliance and certification as the platform and its client base grow.

We do not claim full compliance with any specific regulatory framework unless we hold the certification to back it up.