Trust · security
Nothing is posted without approval; every action is logged. Data is encrypted, US-hosted, and never used for training.
It stops at the draft
Everything the agent creates or edits is a draft. It is written to the database only after a person approves it. Filings, transfers, and invoices are submitted by a person.
No new permissions
The agent uses the caller's ERP permissions as they are. Data outside those permissions cannot be queried at all.
Every action is logged
What the agent read, what it produced, and who approved it and when are kept in the audit log. The log cannot be edited.
Never used for training
Company data is not used to train models. Nothing stays with the model provider after processing.
Approval flow
Of the six steps, people do two: approve and submit. The agent and the system do the rest.
Screens
Values the agent filled in are marked differently. They are easy to tell apart from values a person entered.
The agent reads the purchase order and fills in the fields. Fields it is less sure about get a check mark. It becomes a sales order only when the person in charge presses approve.
What the agent read and produced, and what a person corrected and approved, each on its own line. An administrator can export the audit log.
When Sales calls the agent, it sees what Sales sees. Payroll and journals are outside that role, so they cannot be queried at all.
Details
The questions that come up in every security review, answered item by item. You can send this page to your security team as it is.
The agent only goes as far as the draft. Writing to the database takes a person's approval.
Sales orders, purchase orders, journals, HR records. Everything the agent produces waits as a draft. It is written to the database only after the person in charge approves it, and a rejected draft leaves nothing behind.
Drafts and approved records are stored separately. Apps and reports read approved records only. A draft never shows up mixed into another screen.
Sales tax returns, payroll tax filings, transfers, EDI invoices. The agent produces the file or the document, and a person presses submit. The agent has no credentials to file with the IRS, a state tax portal, or a bank.
A field that is missing from the source, or that reads two ways, gets a check mark. The person in charge starts there.
Anomaly detection, continuous reconciliation, and closing checks run on a schedule. The results reach people as drafts and notifications, and nothing changes the database on its own.
The approver changes with the amount and the document type. Approval lines are set up at onboarding to match your policy, and later changes are made by an administrator in one place.
The agent acts with the caller's ERP permissions. Every action goes into the audit log.
The org chart and roles are the permissions. People, the agent, and apps built with App Builder use the same permission table. Data outside a person's permissions cannot be queried at all.
The agent has no administrator permissions of its own. Called by Sales, it runs as Sales. Called by Accounting, it runs as Accounting.
What it read, what it produced, and which request started it, one entry each. What a person corrected, who approved, and when are recorded alongside.
Entries are append-only. They cannot be edited or deleted. An administrator can export a date range or a user as CSV.
When an account closes, the agent and the apps close with it. When someone changes departments, their permissions change on the spot.
Dashboards and admin panels built with App Builder inherit ERP permissions. When the builder says "Sales only", that is the whole setup.
Company data lives on one database, in US data centers, encrypted.
Sales, inventory, accounting, and HR data are stored on one database for your company. It is never mixed with another company's data.
Stored data is encrypted. Traffic between the browser and the server, and between the server and the model provider, is encrypted with TLS 1.2 or higher.
Data is stored in US cloud data centers. A company that needs a different region chooses it at onboarding.
Data is backed up on a regular schedule. Backup frequency, retention period, and recovery time objective are written into the contract to match your requirements.
Data is kept for the term of the contract. When the contract ends, you download your data and we delete it. The timing and method are written into the contract.
Our operations staff cannot see your data by default. If an incident calls for access, we ask for your consent first, and that access is logged as well.
Models are used only to produce drafts. They are never trained on your data.
Company data is not used to train models. The agent's drafts and the corrections people make are not used for training either.
We hold Zero Data Retention (ZDR) agreements with model providers such as Anthropic and OpenAI. Data is discarded as soon as the model finishes processing. We share the agreements during your security review.
The agent sends the model only the source document and the fields needed for one draft. It never sends the whole database.
Requests made to the agent and the results it produced are kept in your database. An administrator can see who asked for what.
The model produces the draft. The system writes to the database, and only after approval. A wrong call by the model never becomes a record on its own.
Which model providers to use is decided at onboarding. A company that must exclude a specific provider is set up that way.
Sign-in, network, change, and incident handling follow your policy.
People sign in with their company account. We connect the identity provider you already use over SAML or OIDC, and no separate accounts are created.
Accounts that do not use SSO can be required to use two-factor authentication.
Access can be limited to your office and VPN IP addresses. An administrator manages the allowlist.
Tax and form updates and integration changes are applied by us, with notice before they go live. Company-specific changes are made by your staff in App Builder, and those changes are logged as well.
Outages and security incidents are reported to you through a defined procedure. You receive the scope, the fix, and the prevention measures in writing.
The uptime target and maintenance windows are written into the contract. Maintenance happens outside business hours and is announced in advance.
Security review
Ask and we send the documents your security review needs. If your security team has a questionnaire, we answer it item by item.
We walk through the approval flow, the permissions model, and the audit log on your own org chart.