Access, responsibility and human review belong in the workflow.
Agree the boundaries before work starts.
01
Identity and role
Establish the person, team and responsibilities behind the
request.
02
Permitted sources
Define which information the workflow may read and retain.
03
Deployment policy
Agree hosting, model providers and any required retention
restrictions.
04
Action and review
Define what agents may do, which actions need approval and how
results are checked.
A few practical questions
Does EU hosting alone establish GDPR compliance?
No. Hosting location is one part of the assessment. Purpose,
lawful basis, access, retention, processor terms and any transfers
also need to be addressed for the specific deployment.
Is zero retention the default everywhere?
No. We offer zero-retention options where it is a requirement and
the selected service supports the agreed configuration. Retention
in the workspace, source systems and model service must be
considered separately.
What is the current SOC 2 status?
The SOC 2 process is underway. AiAx does not currently claim a
completed examination or report. Ask our team for the current
scope and supporting information.
Our SOC 2 journey is underway.
We have started working towards SOC 2. The process is ongoing; we do
not currently claim a completed SOC 2 examination or report.
Define access around the work.
Each implementation needs an agreed set of sources, users and
permitted actions. A model choice does not replace access controls
or an explicit approval policy.
Keep important decisions visible.
Review points should make clear what an agent proposes, which
information it used and who can approve the next action.
Talk to us about your requirements.
Ask about data handling, deployment and the controls relevant to
your organisation before starting a pilot.