AI you can actually trust with your data

Capabilities

Everything included, nothing bolted on after the fact.

  • No training on your data, ever
  • Zero trust by default
  • Deterministic egress to declared destinations only
  • DLP filtering for PII and export controlled material
  • Per tenant keys, no shared secrets
  • Immutable, append only audit logs
  • NZ data residency options
  • Role based access and least privilege
  • Encryption in transit and at rest
  • Human in the loop on sensitive steps

Every build starts with a fixed-scope conversation, no surprise line items after the fact.

Frameworks and alignment

  • NZ Privacy Act 2020 aligned
  • APRA CPS 234 aligned
  • IRAP pathway controls
  • ISO 27001 and SOC 2 on the roadmap

The build itself, not a proof of concept.

01Your data stays yours

Agents run against your systems inside your boundary. We do not pool your data with other clients and we never feed it into public model training.

02Access controls

Role based permissions, least privilege service accounts and scoped API keys mean every agent only touches what it genuinely needs to do its job.

03Audit logs

Every action an agent takes is recorded with who, what and when, so you can review, explain and prove exactly what happened at any point.

04Data residency

Hosting in New Zealand where you need it, with encryption in transit and at rest, to keep you onside with local privacy expectations.

05Zero trust by default

Nothing is trusted because of where it sits on the network. Every call is authenticated and authorised on its own, so a compromised component does not inherit the run of the system.

06Deterministic egress

Outbound traffic goes to a known, declared set of destinations and nowhere else. An agent cannot quietly reach a service nobody approved, which is the failure mode that makes model driven systems hard to sign off.

07DLP filtering

Personal information and export controlled material are detected and stopped before they leave the boundary, on the way into a model as well as on the way out.

08Per tenant keys

Each client holds their own keys. There is no shared secret whose compromise reaches further than the one tenant it belongs to.

09Immutable audit logs

The record of what an agent did is append only, so the log can be relied on in a review rather than being something an operator could quietly tidy up afterwards.

FAQ

No. Nothing you give us is ever used to train a public model, and we do not pool your data with other clients.

Access is role based, with least privilege service accounts and scoped API keys, so every agent only touches what it genuinely needs to do its job.

Yes. Every action an agent takes is recorded with who, what and when, so you can review, explain and prove exactly what happened at any point.

We host in New Zealand where you need it, with encryption in transit and at rest, to keep you onside with local privacy expectations.

Interested in solving your problems with security?

Tell us what you are trying to do and we will reply with how we would build it, no obligation.

Please see our Privacy Policy regarding how we handle this information.

You get the upside of AI without handing over control, with a system your security and compliance people can review, approve and stand behind.

Let’s talk

Was this helpful?