Businesses hand us tender packs, leases, contracts and financial records. That's a responsibility we design around — from day one, not after enterprise deals demand it.
South African privacy law shapes the architecture: purpose limitation, minimisation, retention rules, and a data processing agreement in plain language.
Your company's data is isolated at every layer — application, database, file storage and AI retrieval. Isolation is tested automatically on every release.
Encrypted in transit and at rest. Secrets in managed vaults. MFA for privileged roles, role-based access for everyone.
Customer content is not used to train foundation models. Any future benchmarking would be aggregated, anonymised and contractual — opt-in, never silent.
Seven authority levels per agent — observe, research, recommend, prepare, draft, execute-with-approval, autonomous — enforced by the runtime rather than by a prompt. Today no agent executes without approval: high-impact actions such as submissions, notices and contracts are refused outright unless a named human has approved them, and the refusal is recorded. Agents run behind feature flags that an owner can switch off.
Every agent run logs its trigger, data touched, model activity, output, evidence and approver. Exportable when your auditors ask.
The regulated boundary (Financial Services AI): the AI prepares, checks, triages and recommends; authorised humans make credit, insurance and other regulated decisions. Every decision records its policy version, evidence snapshot and accountable reviewer. Production rollout in regulated environments follows product-specific legal, compliance, model-risk and security review.
Security roadmap: POPIA readiness, penetration testing and incident response ahead of scale; ISO 27001 readiness as enterprise demand justifies it. Full security pack available under NDA. Request it →