Security and data
How we keep you in control of the agent, and of your data.
Trust in an AI agent comes from knowing what it can reach, what it did, and who approved it. This page explains how we design agents so those answers are always clear, and what we go through with you before anything starts.
How we design
Four principles behind every agent.
You grant the access
An agent works with the access you give it, in the systems you already use, and we ask only for what the task needs. You can see what you have granted, and you can withdraw it.
People approve first
We begin with your team approving every result. Oversight steps back only when accuracy has been proven, only if you choose, and you can turn it up again at any time.
Work you can review
We design each agent so that its work can be reviewed: what it looked at and what it did. Where an answer draws on documents, it shows which ones.
Data handling agreed in writing
How your data is handled is set out in the agreement for each engagement, not left to a general policy. We go through it with you and your security team before anything starts.
Before we start
Questions we settle with you first.
These are the points we work through together, and we are glad to answer them in writing for your security or legal team.
- Which systems the agent may read from, and which it may change.
- What data it will see, and which data is kept out of scope entirely.
- Where the work is processed, and by which providers.
- How long anything is kept, and who can see it.
- Who approves results, and how you can stop the agent at any time.
- What happens to the work and the data if the engagement ends.
What this page is, and is not.
This page describes how we design our work. It is not a certification and it is not a contract. If your organisation needs specific assurances, such as particular standards or audit rights, tell us early. We would rather answer your questions directly and precisely than put badges on a page.
Talk to us about your requirements