Private client environment
Authoritative and identifiable information
- Original customer records
- Customer and supplier names
- Product numbers and contact details
- Confidential specifications
- Commercial information
- Final approved responses
Evidence-backed work requires more than a confidentiality promise. It requires separation, minimum access, human verification and visible client authority.
Read the AI boundaryCore operating rule
“No original customer document, confidential product file or identifiable customer information is submitted to a public or personal AI account. AI-assisted work is limited to fictional, anonymised or appropriately pseudonymised working information, following documented client instructions. All final outputs are checked by an authorised human against the original evidence before submission.”
A. Customer information
Information is processed only for the documented scope and is limited to authorised personnel.
A project may require controlled access to the following types of customer information:
The public website does not provide a general document-upload function. Evidence is requested only after qualification, confidentiality discussion and written agreement.
B. Separated environments
The dividing line applies to documents, names, identifiers and commercially sensitive context—not only to personal data.
Private client environment
AI-assisted working environment
Pseudonymised does not mean anonymous. It may still be personal or confidential information and must continue to be protected, access-controlled and handled under the agreed instructions.
C. Human review
Every answer must be supported by client-provided or client-authorised records. Unsupported claims are marked as gaps, conflicting evidence is escalated and the client confirms accuracy and disclosure.
D. Data minimisation
Only information reasonably required for the agreed work should be requested, accessed or transferred. Irrelevant identifiers and document sections should be excluded where practicable.
E. Retention and deletion
Project retention periods are agreed in the client contract. Documents are returned, retained or securely deleted according to those instructions and applicable legal requirements. No universal period is assumed.
F. Service providers
External providers are used only where appropriate contractual, confidentiality and security controls are in place. Named subprocessors will be published only after the production technology stack is approved.
G. Designed security controls
Our production system is designed to use the controls below. Final implementation, supplier due diligence and testing must be confirmed before a secure client portal is released.
Administrator and authorised-user access
Only the permissions required for the agreed work
Named recipients and project-specific access
Protected transfer between approved systems
Client-approved production repositories
Access, version and release events where supported
Documented recovery appropriate to the service
Escalation, containment and notification procedures
Revocation after completion or role change
No visual login page is presented as a working secure system. Authentication, recovery, session control, audit logging and vulnerability testing must be complete before release.
Production release gate
Related controls
Start with the live request
Check fit privately, then start a non-confidential conversation about the deadline, scope and evidence condition. No files are uploaded through this website.