Where your data sits,
and who can see it.
Access is scoped by active assignment. Never by tier, never by seniority.
What we do not claim
No certification is claimed
No SOC 2, HIPAA, ISO, FedRAMP or GDPR certification is held, and none is asserted. Where a control is designed but not yet operating, we say so rather than describing intent as fact.
Encryption at rest is vendor provided
It is a property of the subprocessors in the published register, and it has not been independently verified by us. It is stated here as what it is.
The assistant is scope tested, not adversarially tested
Isolation has been tested for scope adherence. Adversarial testing is a condition before the public assistant goes live, and it is named as such rather than assumed.
How access works
What Ari will not do
Ari is present across the whole journey. Its limits are published for the same reason the scale is.
The documents behind the claims
Every statement on this page has a document behind it. These are those documents.
Security FAQ
How data is held, transmitted and separated, and what has and has not been independently verified.
Read the FAQCookie notice
What is set, why, and what happens when you decline. Non-essential is off by default.
Read the noticeAI use notice
Where AI is used, what it writes, what it never writes, and what it is never given.
Read the noticeSubprocessor list
Every vendor that processes, transmits or stores client data. Generated from the internal register, never maintained separately.
See the listCommitments
No training on client data
Your programme data is never used to train a model.
Attribution on every record
Every gate decision carries a name and a date.
Method published
You can check the measurement before you trust the number.
Questions before you start
Ask anything about data handling, scoping or the record format.
Loop Insights
Framework implementation, the Orien case work, and the questions worth putting to a steering committee. Published openly.
Read the insights