Data security
What happens to your company's data when you work with us
We give these answers to every corporate client before we start. Here they are in one place, so your security team or IT director can read them on their own — before the call, not after.
In short
Five things worth knowing first
01
No access needed to start
We deliberately build the first automations on tasks that need no 1C, Odoo, CRM or confidential data: moving documents between PDF, email, Telegram and spreadsheets, reports, reminders, collecting information from open sources.
02
Training runs on test or anonymised data
Sessions use test or anonymised data. The company's confidential information is not needed for training.
03
Automations live on your servers
Finished automations run on your infrastructure. We do not need your access for them to work, and after the programme you do not need us.
04
Access and keys stay under your control
Your side decides who can access what — access stays under the company's control. In the corporate AI core, access rights and keys are kept in one place, not scattered across employees' personal accounts. The separate support subscription — if the company takes it — moves hosting of the core and its keys under our supervision; that is a separate choice after the programme, not a condition of the implementation.
05
AI subscriptions are yours
The company buys AI tool licences directly from the vendors, on its own accounts. We do not resell them and take no commission.
Cloud and perimeter
What may reach a cloud AI service and what stays inside
- A cloud language model sees only what a specific automation passes to it. So the boundary is drawn in the technical spec: for every automation we write down what it takes as input, where it sends the result, and what it does not do.
- What may go to cloud AI services and what stays inside the company is a dedicated session of the programme, not an ad-hoc call by each participant.
- If real data cannot travel to third-party clouds, we deploy the solution on your servers.
Internal systems
How automations connect to your systems
- Automations connect to 1C, Odoo, CRM or the knowledge base through your gateway and under your access and role rules.
- For reports and analytics we use a read-only copy of the database: the automation changes nothing in the production system.
- Exactly how automations plug into your platform is a separate piece of work with your IT team, not a precondition for starting.
Risks
Where the real risk is and what we do about it
- The language model only reads and classifies the input. Money, routing and escalation are code, and output to a customer goes only through a person. The same input gives the same output, and every automation has test cases and acceptance criteria.
- The main real attack vector on an AI agent is prompt injection — instructions hidden in someone else's text. So the agent does not roam third-party websites, gets a read-only copy of the database, runs on company subscriptions rather than personal ones, and any password that had to be shown to an AI assistant during setup is changed afterwards.
Contract
Contract and confidentiality
- The subject of the contract is “information and consulting services for the practical implementation of AI in business processes”: this is implementation, not an educational service. If your lawyers prefer other wording, we have it ready.
- Confidentiality is a standard section of the contract. We will sign a separate NDA if your security team requires one — on your template or ours.
- Each stage has a contract with a specification and an invoice, and once it is done, an acceptance act for the sessions actually held. You do not prepay the whole cycle. We attach a DOCX for your lawyers' edits and can work on your contract template.
- The contractor's liability is limited to the amount paid for the stage; the contractor is not liable for how third-party software and AI services perform.
- The contractor is a Ukrainian single-tax payer and is not a VAT payer; amounts exclude VAT. Company details, a state-register extract and activity codes are sent on request the same day.
Ownership
What stays with you
- The automations, process maps, session recordings, templates and working materials stay with the company. There is no subscription fee for the programme.
- The methodology and programme materials remain the contractor's; the company receives a licence to use them for its own internal needs.
To be clear
What we do not claim
- We do not cite certificates such as ISO 27001 or SOC 2. Security here rests not on paper but on what is described above: access stays with you, automations run on your servers, training needs no confidential data.
- How AI vendors treat data from corporate accounts is a matter of their terms, not our promises. We send your security team links to the official documentation of the vendors your company chooses, in writing.
Questions
Does your security team have its own questionnaire?
Send it over and we will answer in writing, point by point. That is how we work with corporate clients: written answers for security first, then a pilot on one team or process, then a decision to scale.