Your data, your decisions — in writing
Written for a business owner deciding whether to trust an AI service with company knowledge, not for a compliance department.
Nothing is used without your signature
Before anything is connected you sign a one-page scope approval: the exact folders, documents and systems that are in. Anything not on that page is out — including other folders in the same drive. When the scope changes, the page is re-signed.
You decide what's in scope
It's your data. If you want your mailboxes searchable by your own staff, that's your call to make and we'll build it. If you'd rather they never were, that's equally your call — and far more common.
What we bring is the conversation most suppliers skip. Some material carries risk that isn't obvious until someone points at it: mailboxes and chat archives are dense with customer personal data and HR matters; a historical support archive is full of one-off concessions and superseded policy that an assistant will happily repeat as though it were current. We tell you where those edges are, recommend where to draw the line, and then sign whatever you decide.
Most clients end up excluding payroll, personnel files and raw mailboxes. That's a recommendation they accepted, not a rule we imposed.
Three things you can do with any source
The middle one matters most in practice. Your mailboxes can be connected — so a drafting service works on one named flow of enquiries — while remaining unsearchable by staff. Different permission, different agreement. If a supplier uses those two words interchangeably, ask which they mean.
When your own people build things
- The AI only sees what the person asking may see. It can't be talked into looking somewhere they couldn't look themselves.
- Nothing goes live because an AI decided it should. Every draft is previewed against real data and published by a named human, with the approval recorded.
- Outward-facing work is drafted, not sent. A reply to a customer is written into the tool your person already uses. They read it, edit it, send it — as themselves.
- Anything that genuinely acts is stage-gated. Writing into a system of record, or sending without a person in the loop, requires all six: a written declaration, its own signed scope, its own narrow credentials, a recorded switch-on with a named approver, human approval of what it does, and an audit record written before each run.
The platform isn't incapable of acting. It's built so acting is always a decision somebody made on purpose and signed their name to. Nothing acts quietly.
Your own environment
A dedicated, isolated cloud project: your documents, your database, your search index, your credentials, and anything your team builds — used by your business alone. Not a multi-tenant platform where your data shares a system with strangers'. Staff sign in with the Google or Microsoft accounts they already have, and who sees what is enforced on the server, per person.
Reading is governed exactly like asking
Your team can read approved documents as pages, not just ask questions about them — and the same permission check applies to both. A document in an area someone hasn't been granted doesn't appear in their library and can't be opened by pasting its address. It comes back as not found rather than you're not allowed, deliberately: knowing that a document exists is itself information, and staff shouldn't get it by guessing.
What we can see, and what we can't
We operate your environment, so it's fair to ask what that lets us look at. We see totals, never contents: how many questions were asked this week, how many went unanswered, whether the sync failed, whether the index is empty. We do not see a single question anyone asked, who asked it, or what any of your documents are called.
That isn't a promise about our manners — it's built the way round that makes it checkable. Your environment only ever sends us a summary, and if one ever started sending more than that, the summary is withheld rather than passed through. It's the reason it's reasonable to let anyone else run this for you.
Citations, because trust needs receipts
Every answer names the document it came from. Staff check the source in one tap; a wrong answer becomes a ten-minute document fix instead of a mystery. The assistant answers from your approved material — it doesn't freelance from the internet.
Where data goes
- Documents and conversation history stay in your own UK/EU-region cloud project, deleted on a retention schedule you choose (90 days by default — longer if you have a reason).
- To answer a question, it and the relevant excerpts go to the AI model provider under business terms — not used to train their models.
- Admin actions are logged and visible to you.
It will sometimes be wrong
Anyone who tells you otherwise is selling something. Ours is wrong visibly — with a citation pointing at the document to fix — and reviewed weekly for the first month, monthly after. The loop is what keeps answers right, not the promise.
The exit is documented too
If you leave: your documents returned, the environment deleted, deletion confirmed in writing. Judge a supplier by how well-documented their goodbye is.