Security and data handling

AI for the files you can't paste into a chatbot.

Every system we build runs in accounts your business owns, on your own AI keys, with a record of who touched what. For privileged and regulated work, it can run entirely inside your own environment.

YOUR ENVIRONMENT · PRIVATE DEPLOYMENTCLIENT FILESAI MODELYOUR SOFTWAREACTIVITY LOGWORK-FLOWAUTOMATE-NEXUSREVOCABLE

Who holds what

You keep the system, the accounts and the data.

Who holds itYour companyAutomateNexus
Client documentsYoursNo copy kept
AI provider account and keysYoursNone
Workflows and sourceYoursHanded over at launch
Activity logYoursRead on request
Access after launchYou decideRevocable at any time
/ CUSTODY/ FIG. 01

Where it runs

Three ways to deploy, chosen by what your documents require

Your own hosted accounts

The system runs in cloud accounts in your company's name, calling an AI provider through your own key on a plan that excludes your data from training. The usual choice for work that is sensitive but not privileged or regulated.

Private cloud

The model itself runs inside a cloud account you control, so documents and prompts are never sent to a public AI service. For privileged and regulated material.

On site

The model and the document index run on a machine in your office. Nothing leaves the building. The hardware is bought at cost and belongs to you.

How we build

Six rules on every engagement

A person approves

Anything that sends a message outside the company, posts to a ledger or changes a client record waits for a named member of your staff unless you have told us in writing that it may run alone.

No automated decisions about people

We do not build systems that decide on their own who is hired, insured, housed, lent to or treated. Those calls stay with your people; the system prepares the file.

Least access

Each connection gets the narrowest permission that does the job, on its own credential, so it can be switched off without touching anything else.

Everything is logged

What ran, on which record, with what result, and who approved it. The log lives in your accounts and is yours to keep.

A written data record

At handover you receive a document listing every system the data touches, whose account it is in, and what is retained. It is written to drop into your own security plan.

We leave when you say

Our access is granted by you and can be revoked by you at any time. After launch we hold access only if you ask us to, under the care plan.

Questions

Security questions

Is our data used to train AI models?

Not in the systems we build. Hosted deployments use business plans and API settings that exclude your data from training, and private deployments never send it to a public AI service at all. The configuration is written into your data record.

Where is our data stored?

In accounts your business owns. We tell you which ones before the build starts, and the list is part of the handover documentation.

Do you keep copies of our documents?

No. Work is done inside your accounts. Sample documents you send us for scoping are deleted when the build is delivered, or sooner if you ask.

Can you sign a business associate agreement?

Yes, where a build involves protected health information. We also confirm that each third-party service in the build will sign one before we use it.

What happens if we stop working with you?

Nothing stops. You revoke our access and the system keeps running in your accounts on your keys, with the documentation to maintain it.

Does a private deployment make us compliant?

No system does that by itself. It gives you control over where data goes and a record you can show, which is what your professional and regulatory duties ask of you.

Where we go from here

Ask us the hard questions.

Bring your security questionnaire or your compliance lead to the first call. If we cannot meet a requirement, we will say so then.

No subscription.

No lock-in.

No surprise invoices.

Or start smaller — the $500 pilot · see pricing

/ START HERE/ FIG. 14