Isolation you can verify

Direct answer

Isolation here is a boundary, not a filter. You get your own application and your own database, so another customer’s system is refused permission to reach yours — rather than being trusted to ask only for its own rows.

And it is checked by machines, not only by reviewers: the release pipeline fails automatically if code attempts a data query without correct customer scoping.

The wall

Real, not a column.

Most platforms separate customers with a tenant identifier filtered inside one large database. One bad query crosses the line.

Dedicated database

Its own application and its own database. No shared production database holds two customers' data.

Denied at the database level

A different customer's system is refused permission to connect to yours. Not a filter — a boundary.

Enforced in the build

The release pipeline fails if a query runs without correct scoping. Verified continuously, not asserted once.

Permissions inside

Role-based access, workspace separation, per-user credentials. Colleagues do not inherit your connections.

Second factor on sensitive actions

Deleting a workspace, unmasking personal data or running an erasure each need a fresh one-time code.

Oversight without snooping

Admins may review for quality and safety, but personal data is masked by default. Unmasking is logged.

Why we frame it this way

A certification attests that controls were designed and operating across a window. It cannot assert that a dedicated database exists for you, or that a release is blocked when scoping is missing.

Privacy engine

Personal data is handled first, not filtered last.

Recognition, redaction, routing and rights — as product behaviour rather than policy.

Recognises it

Australian, US and EU identifiers plus emails, phones and cards — real validation, not pattern guesses.

Keeps it out

Always-on log redaction. The audit trail records what kind of data was involved, never the data.

Routes it

Sensitive content reaches only providers under contractual no-training terms — by default, Anthropic.

Answers requests

GDPR, CCPA and Australian Privacy Act tooling, with the legal clock tracked and erasure safe under hold.

Where does our data actually go?

Into your dedicated database. Only no-training providers may see sensitive content. Everything produced stays inside your instance. Nothing lands in a shared pool, and nothing trains a public model. Consumer AI tools are blocked unless an admin makes a deliberate, logged, reversible exception.

Ownership

You own the instance. You own the data.

Regional cells, with a clean exit written in from the start.

The instance

Dedicated to you, operated on your behalf.

The data

Your property. We make no claim over it and do not train models on it.

Your region

Australia and the United States are live. Your instance is provisioned into your region at onboarding.

Clean exit

Exportable. On offboarding the instance and its data are returned or destroyed.

Governance

Trust is structural.

Not a compliance page bolted on at the end.

Existing systems stay central

Your systems of record remain authoritative. No migration is required.

Scoped access

By workspace, channel, client and organisation — and by contractual boundary.

Human approval modes

Workflows prepare and recommend, then wait at gates a named person passes.

Audit trails

What ran, what it produced and who approved it — recorded as it happens.

Evidence links

Recommendations carry their sources, and name the evidence that is missing.

Connector permissions

Each connection granted explicitly, and withdrawable.

The five stages, and what holds a run

Enforced in the product

Read from the live control plane, not from a policy PDF.

Each of these is read off the running product — settings a reviewer can be shown, not statements a document makes.

POLICY GATE

Asked before, not filtered after

One PII taxonomy, one gate — every surface consults the policy before it acts. Jurisdiction detector packs switch on per tenant as data, not a deploy — enforcement never flips fleet-wide.

GRANT CEILINGS

Bound to named tools

A channel is granted individual tools — never a whole server. Nothing said inside a channel can widen what it may reach, so instructions arriving in a conversation cannot escalate it.

LOG REDACTION

Always on. Not a setting.

Every log, trace and error line is stripped of credentials and sensitive-tier identifiers — tax file numbers, government IDs, cards, bank identifiers — before it reaches any sink, independent of policy state.

OPERATOR LEDGER

The admins are audited too

Every admin change records itself — who, what, where, when. Oversight queries run with the asker’s permissions, nothing more, audited under their name.

Customer zero, read from the live admin surface. These are the mechanisms behind the claims above — ask to be shown them in a briefing.

Stated honestly

What is not done, and what is per engagement.

We would rather lose a deal than overstate a control.

SOC 2 — in preparation

Controls built to the Trust Services Criteria, evidence being collected. Not an issued report, and we will not describe it as one.

Sub-processor register and DPA — in preparation

On request as finalised, published in full before enterprise launch.

US region — per engagement

A provisioning step at onboarding. Live today is Australia.

Private network, BYOK, pen-test report — per engagement

Production tier. We will not imply they are switched on for a trial.

Common questions

What security reviewers ask first.

If a control is not in place we say so on this page, not in the follow-up call.

How do you know the isolation still holds?

Because it is checked on every release. The build fails if code attempts a data query without correct customer scoping. Isolation asserted once at design time is a weaker guarantee than isolation verified continuously.

Which model providers see our data?

Sensitive content reaches only enterprise providers under contractual no-training terms — by default, Anthropic. Consumer AI tools are blocked unless an administrator makes a deliberate, logged and reversible exception.

You are not SOC 2 certified. Why proceed?

Weigh it honestly. A SOC 2 report attests that controls were designed and operating over a window; it does not assert that a dedicated database exists per customer, or that a release is blocked when scoping is missing. We are in preparation, we will say so until it is issued, and we are happy to be assessed on what is in place today.

Can we run in our own region?

Australia is live. A US instance is stood up as a provisioning step at onboarding — a clean dedicated deployment in your region, not a shared existing footprint.

Bring your security team to the briefing