Security, privacy & control

Enterprise AI shouldn't require giving every agent everything your organization knows.

DM is designed around data minimization, purpose limitation, scoped access, human approval, and customer-defined deployment boundaries. Only the permitted knowledge that applies to the task should be activated.

Data protection by design

Privacy is an architectural constraint, not a footer claim.

DM's architecture is designed around the GDPR principle of data protection by design and by default: minimize what is processed, keep purpose and scope explicit, restrict access, and make data boundaries visible. We do not claim GDPR certification or an audited compliance status — this is an architectural commitment, and formal compliance claims are made only where legal and technical documentation support them.

Selected, not silently crawled

Evidence you choose

DM operates on evidence users intentionally add, or sources explicitly configured for the workflow — a document, transcript, ticket, or connector you turn on. There is no background crawl of your whole workspace.

Minimum applicable context

The smallest useful subset

A task should receive what is current, relevant, in-scope, and authorized — not the whole knowledge store. Out-of-scope or unauthorized knowledge stays out. This is a context-quality advantage and a privacy advantage at once.

Human authority

Agents propose. Humans decide.

Agents may propose candidate knowledge from evidence or their own work. A human reviews, edits, rejects, or approves. Nothing is autonomously promoted to authoritative organizational knowledge, and every change stays traceable to its provenance.

Workspace & tenant boundaries

Scoped and permission-aware

Every record carries the scope it applies to. Retrieval is permission-aware, and nothing crosses a tenant or workspace boundary it wasn't approved for.

Deployment

Data boundaries and deployment.

One maturity model, used everywhere on this site: what runs today, what we provision with you during onboarding, and what is still planned.

Available now

Running in DM today.

  • Managed DM AuzzurA operates the DM application and its data stores for you. Managed deployments can be provisioned in an EU cloud region. All plans
  • Control and Knowledge kept apart Account and workspace control data and your Knowledge — Decisions, Rules, Skills and their evidence — live in physically separate databases. All plans
  • Workspace-bound Knowledge Store Each workspace resolves to its own Knowledge Store binding. A missing or broken binding fails closed — it never falls back to another workspace’s store. All plans

Provisioned during onboarding

Built and tested. Set up with AuzzurA for your workspace — not self-service.

  • Dedicated Knowledge Store Your workspace Knowledge on its own database instance, provisioned and migrated with AuzzurA. Business · Enterprise
  • Customer-controlled Knowledge Store (BYODB) Your Knowledge on a supported database you control, connected to DM and migrated with AuzzurA during onboarding. Enterprise

Planned

Architecture direction. Not available yet.

  • Bring Your Own Key (BYOK) Customer-managed encryption keys for your Knowledge.
  • Bring Your Own Model (BYOM) Your own model provider or approved model endpoint for AI-assisted steps.
  • Customer-operated DM Running the full DM application inside your own environment, and self-service store provisioning.
  • Retrieval is permission-aware: an agent or user only reaches what their scope authorizes.
  • Provisioning a dedicated or customer-controlled Knowledge Store, and migrating existing Knowledge into it, is done with AuzzurA during onboarding — there is no self-service store setup yet.
Onboarding

Evidence & onboarding.

  • The evidence boundary — what can be used, and what stays out — is agreed with you before any evidence is shared.
  • Residency, retention, access, and deletion requirements are agreed in writing as part of your customer agreement.
  • Confidential, customer, or sensitive data should not be submitted through the public website forms — every deployment has its own designated evidence channel.
Models

What is sent to models?

What can reach an LLM

Only the permitted, in-scope subset of governed knowledge resolved for the specific task — not the full knowledge store — is sent to the configured model to draft a candidate or generate a response.

Model training

We do not publish a blanket model-training guarantee here. Provider configuration, logging, and retention behavior are documented and agreed as part of your deployment. Bring Your Own Model — using your own provider contract to govern training and retention directly — is planned, not available yet.

FAQ

Trust, quickly.

Does DM crawl our entire workspace?
No. DM operates on evidence users intentionally add or sources explicitly configured for the workflow — not a background crawl of everything the company has.
What does an AI agent actually get access to?
Only the permitted subset of governed knowledge that applies to the task in front of it, resolved by scope, authority, and lifecycle — not the entire knowledge base or every rule file.
Can we keep data in our own environment?
Managed DM is available now, with Control and Knowledge data in physically separate, workspace-bound stores. A dedicated or customer-controlled Knowledge Store (BYODB, Enterprise) is provisioned with AuzzurA during onboarding. Bring Your Own Key and Bring Your Own Model are planned, not available yet.
Is DM GDPR compliant?
We do not claim certified or audited GDPR compliance. DM is designed around data-protection principles such as minimization, purpose limitation, scoped access, and customer-defined data boundaries. Hosting, residency, retention, subprocessors, and other legal/technical requirements are agreed as part of your deployment. See our privacy notice for the current legal detail.
How are candidates approved?
Imports, AI-drafted extractions, and agent write-back are all candidates. A human reviews each one against its evidence and either approves, edits, or rejects it. Nothing becomes durable organizational knowledge without that step.
Talk to us

Discuss your security and data-boundary requirements.