Security & Trust

AI you can let near
your system of record

An AI layer that reads and writes ERP data has to be held to a higher standard than a chatbot. Here is how we hold ourselves to it — at a high level. For the detailed architecture and controls, talk to us directly.

Our approach

Six commitments, engineered in

Human-in-the-loop by default

No transaction reaches SAP or any system of record without explicit human confirmation. AI prepares; people approve. That boundary is architectural, not configurable away.

Role-based access control

Every user's access is scoped to their role, and permissions are enforced when the query runs — an employee and a CFO asking the same question get answers scoped to what each may see.

Your tenant, your boundary

Deployment in your Azure, AWS, or GCP tenant — or on-premise. Enterprise data stays inside your network boundary, your identity model, and your governance.

Encryption throughout

Data encrypted in transit and at rest, credentials held in managed secret stores, and service-to-service authentication on every internal call.

Complete auditability

Questions, generated queries, retrieved data, and posted transactions are logged end to end — "who did what, when, and based on what data" is always answerable.

Least-privilege integrations

Connections to SAP and other systems use dedicated service accounts with the minimum authorisations the workflow needs — never blanket admin access.

Standards

Built for regulated environments

We design and operate our systems to work within the compliance frameworks our clients are held to.

Data protection

GDPR-aligned

Data minimisation, purpose limitation, and data-subject rights considered in the design of every workflow that touches personal data.

Operational controls

SOC 2-aligned practices

Access management, change control, monitoring, and incident response practices modelled on the SOC 2 trust criteria.

Information security

ISO 27001-aligned

Risk-based security management aligned with ISO 27001 controls, applied across development and operations.

We deploy inside our clients' certified environments and inherit their compliance boundary. For certification status, security questionnaires, and detailed control documentation, contact our team — we're glad to go deep under NDA.

Want the detailed picture?

Architecture diagrams, data-flow documentation, control mappings, and answers to your security questionnaire — our engineering team will walk yours through all of it.