Answers for your security team

This page is written for information security professionals: where data is stored, who can see it, what an AI agent can and cannot do, and how to verify all of it.

Data

Where the data is and who sees it

Where data is storedIn the deployment option you choose: BlackGust Cloud in-region, your private cloud, your own servers, or an air-gapped environment. Personal data stays in the jurisdiction its law requires.
Is data used to train models?No. Cloud models are accessed through enterprise APIs whose terms exclude training on customer data. Local models run entirely inside your infrastructure.
What goes to external modelsOnly the fragments needed to answer. Personal data is masked before it leaves. In air-gapped deployments, external calls are disabled completely.
Who at BlackGust has accessOnly the named engineers on the project, as agreed with you and for the duration of the work. All access is logged and revoked at handover.
EncryptionData is encrypted in transit and at rest. In on-premises deployments, the client holds the keys.
Data deletionAt the end of the contract, data is deleted within the agreed period and a deletion certificate is issued.
Agents

What an AI agent can and cannot do

An agent never gets more rights than the person it acts for. Every limit is set in configuration and enforced by the platform, not by the model.

Can

  • Read data within the user's permissions
  • Draft documents, letters and reports
  • Create tasks and reminders
  • Perform pre-approved actions

Cannot without human approval

  • Change or delete data in systems of record
  • Send documents outside the organization
  • Execute payments or legally binding actions
  • Expand its own permissions
Controls

Control mechanisms

Access

Role-based model

Roles are inherited from Active Directory or LDAP. Object access is restricted down to rows and fields.

Audit

Full audit trail

Every query, answer, source and action, with timestamp and user. Exportable to your SIEM.

Approval

Human in the loop

Threshold rules on amount, document type or new counterparty route an action for sign-off.

Quality

Reference testing

A set of control questions runs before every agent update. A drop in quality blocks the release.

Protection

Input filtering

Incoming requests are checked for attempts to override instructions or reach other users' data.

Contract

NDA and obligations

A non-disclosure agreement before the diagnostic. Data-protection obligations in the main contract.

Verification

Vet us before work begins

We'll provide an architecture description and threat model, and complete your security questionnaire. An engineer can meet your security team before the contract is signed.