Commitment
Security
and trust
How the platform is protected
The measures belong to the core on which every platform is built. They cover who gets in, what each person can see, how the data is stored, and what record is left of every action.
Identity
Access is by invitation only: no one signs up on their own, and only those the organization invites get in. Sign-in uses multi-factor authentication (MFA) and the organization’s enterprise single sign-on (SSO).
Permissions
There are six roles, with granular permissions by section. Each person works with the role assigned to them and sees the sections that role allows.
Data
Row-level security is applied on every sensitive table. Access is decided row by row in the data layer, so two people looking at the same section see only the rows their permissions allow.
Audit
Every action and every AI query is logged. For each query the log keeps the user, the module, the provider, the tokens, and the cost, so the way a conclusion was reached can be reviewed afterward.
Encryption
Data is encrypted in transit and at rest. The encryption is post-quantum ready: it is designed so that its algorithms can be replaced as the post-quantum standards are adopted. The aim is that what is captured today cannot be decrypted later with a quantum computer.
Compliance
GDPR and Spain’s LOPDGDD are applied by design. Evidence is preserved with a SHA-256 chain of custody, so it can be presented in an audit exactly as it was collected.
Private deployment
When the data cannot leave, the platform runs on open models inside the client’s own infrastructure.
Jurisdiction
The platforms are in use in Europe, the United States, and Latin America. Hosting and processing of the data comply with the legal requirements of each country and region where we work.
External review
Security is supervised internally. In addition, an external audit is carried out every year, along with penetration testing, as the standards require.
Human decision
Every fact has a source.
The platform proposes.
A person decides.
Nothing ships unreviewed.
AI amplifies human judgment. It does not replace it.
Every fact has a source, and the recommended decision is traceable to the source data. Claims are checked against traceable evidence, and the six agents’ reports are cross-checked before they reach a person.
Silence is the default. An internal alert comes with context, history, and a recommended response, and a public action is always previewed before it is published. Whatever is published, the organization publishes, through its own channels and after reviewing it.
Europe requires
traceability.
GDPR and the EU AI Act ask where each conclusion comes from and who makes the call. Here, that is built in from the start.
The first question is answered by the source kept with every fact and by the log of every AI query. The second is answered by how the platform works: it proposes, and a person decides.
Frequently asked questions
Who can access the platform?
Only those the organization invites, each with the role assigned to them. Access is by invitation only, with MFA and enterprise SSO, and there are six roles with granular permissions by section.
How is the data protected?
Data is encrypted in transit and at rest, with post-quantum readiness, and row-level security is applied on every sensitive table. GDPR and Spain’s LOPDGDD are applied by design.
Is there a record of what the AI is asked?
Yes. Every AI query is logged with its user, module, provider, tokens, and cost. Every action in the platform is logged as well.
Does the platform publish or respond on its own?
No. The platform proposes and a person decides; nothing ships unreviewed. Silence is the default. Whatever is published, the organization publishes, through its own channels and after reviewing it.
How do we know where each conclusion comes from?
Every fact has a source, and the recommended decision is traceable to the source data. Every action and every AI query is also logged.
We do not name our clients.
Confidentiality is part of the service: here we speak of industries.