Skip to content

Security and responsible AI

What we do with your data, and where the model stops.

Written for the person who has to sign this off. Where something is a fixed property of how we work, it says so. Where it is agreed per engagement, it says that instead of pretending otherwise.

Design rules

Four things that are true of everything we build.

These are not configuration. They are how the workflow is shaped, which is why they survive contact with a deadline.

A person approves anything consequential

Workflows we build prepare, evidence and route work. Where an outcome affects someone — a decision, a payment, a message to a customer — a named person approves it before it leaves. This is a design rule, not a setting that can be quietly switched off.

Every automated step leaves a trail

What ran, what it read, what it produced and who approved it are recorded. If you are later asked to justify a decision, the answer is in the record rather than in someone’s memory.

Access follows the job

Role-based permissions are part of the build rather than an afterthought. People see the work they are responsible for, not everything the workflow touches.

We tell you what the model cannot do

Confidence thresholds, the cases a workflow will refuse to handle, and what happens when it is unsure are agreed before build and documented after it.

This website

What aivomate.com itself does.

Verifiable from the page you are reading. Open your browser's developer tools and check any of it.

How is the site served?
Over HTTPS only, with HSTS set to two years including subdomains. A Content-Security-Policy restricts what the page may execute and where it may send data; the allowed destinations are our own automation service and our analytics host, and nothing else.
What runs in your browser?
Our own JavaScript and self-hosted fonts. No advertising or tracking networks, no third-party scripts beyond the analytics tag described below.
What about the assistant?
The chat widget sends what you type to our automation service with a random session identifier so the conversation survives moving between pages. That identifier lives in your browser’s session storage, is not linked to you, and is cleared when you refresh or close the tab. Your messages are processed by an AI model to generate a reply and may be reviewed by us to improve the service.
And analytics?
A self-hosted, cookieless analytics tool that counts page views. It stores no identifier on your device, does not retain your IP address, builds no cross-site profile, and is not loaded at all if your browser sends a Do Not Track or Global Privacy Control signal.

Per engagement

Agreed in writing before we build.

These depend on your requirements, your regulator and your existing estate, so a single answer for all clients would be a fiction. Here is the list we work through with you, and our position on each.

Control Our position
Where data is hosted Named in the proposal, including region. UK or EU processing where you require it.
Encryption In transit and at rest, using the platform’s managed encryption unless you require your own keys.
Authentication Your existing identity provider where you have one, including single sign-on.
Retention Agreed per data type before build, and implemented as a deletion job rather than a policy document.
Audit logs Retained for the period you specify and exportable.
Backups Frequency and restore target agreed with you, and the restore tested rather than assumed.
AI model providers Named before build. You are told which provider processes what, and where.
Training on your data No. We use providers and settings under which your content is not used to train their models, and we will confirm that in writing for the specific provider.
Subprocessors Listed on request, with notice before any change.
Data processing agreement Available. We will sign yours or provide ours.
Incident handling A named contact, an agreed notification window, and the reporting the UK GDPR requires.
Penetration testing Arranged where the engagement warrants it, and we will not object to yours.

If your procurement team has a security questionnaire, send it to info@aivomate.com and we will complete it rather than asking you to accept this page instead.

Where we will tell you not to automate

Some work should stay with a person, and saying so is part of the job. We will advise against automating a step where the cost of being wrong falls on someone who did not choose the system, where the reasoning has to be explainable to a regulator and the model cannot explain it, or where the volume is too low for the workflow to ever pay for the scrutiny it needs. You will hear that during discovery rather than after the invoice.

Have a security questionnaire?

Send it over. We would rather answer your questions in your format than ask you to take a marketing page on trust.