SECURITY & PRIVACY

Your data stays yours.

Customer data is central to how CIOS works. Your organisation's data remains controlled, isolated and accessible only to authorised users and the services required to operate CIOS.

Built for organisations that need AI on sensitive customer information without losing sight of where it goes.

YOUR ORGANISATION OTHER TENANT OTHER TENANT

OUR APPROACH

Isolation first

Customer environments and organisational knowledge are separated by design.

Least access required

Users and services receive only the access needed for their role or task.

Traceability over black-box AI

Insights stay connected to their supporting signals and organisational context.

Transparency over theatre

We separate controls implemented today from controls still being strengthened.

ACCESS & PERMISSIONS

Deny by default. Grant by role.

Access depends on an authenticated user, their organisation and their assigned permissions. The backend is the authoritative enforcement layer.

Role-based access control Deny by default Invitation-only organisations Server-side sessions Auth0 + OAuth Expiring API credentials Request throttling

DATA PROTECTION MODEL

Security & privacy built for sensitive organisational data.

CIOS works with sensitive customer signals, business context, internal documents and, where required, employee-related data — so data protection is part of the platform architecture, not an add-on. Strong default safeguards combine with flexible deployment and LLM options, so each client can choose the protection model that matches their regulatory, operational and data-sensitivity requirements.

01 — TRUST BY DEFAULT

Strong safeguards, on from day one.

Tenant isolation

Each client environment is separated so customer, business and employee data cannot mix across organisations.

Encrypted by default

Data is protected in transit and at rest using modern encryption standards.

Role-based access

Users only access the data, insights, missions and tasks they are authorised to see.

Traceable intelligence

Outputs remain connected to the underlying signals and sources, so insights can be reviewed and challenged.

02 — LLM OPTIONS

CIOS is LLM-agnostic.

Default LLMs

CIOS routes each task to the best-suited model automatically, balancing cost efficiency and effectiveness.

Custom LLM routing

The client chooses which specific LLM handles their workloads, with control over provider and model selection.

Internal enterprise LLM

CIOS connects to the client's internal enterprise LLM, using existing model contracts instead of external public APIs.

Local / on-prem LLMs

Local or on-premise LLMs deployed on the client's own virtual servers, so sensitive data never leaves their infrastructure.

Model selection is fully configurable. The client decides which LLM provider, routing strategy or environment is appropriate for their data-protection requirements.

03 — PLATFORM DEPLOYMENT

Choose where CIOS runs.

DEFAULT

Standard EU cloud

CIOS hosted on EU-region cloud infrastructure — the default for most clients and standard customer-experience use cases.

Local deployment

CIOS deployed in a client-specific region, meeting data-residency and jurisdictional requirements.

On-prem deployment

CIOS deployed inside the client's own infrastructure — the strongest data-residency and control posture.

AI DATA HANDLING

AI reasons over your data. It never becomes the model.

CIOS uses external AI models as reasoning components, not as the permanent home of your customer knowledge.

CIOS does not use customer data to train a shared CIOS model.

YOUR SIGNALS AI REASONING INSIGHTS IN CIOS

TRACEABILITY

Every insight traces back to its evidence.

CIOS keeps the links between signals, insights, missions, tasks and outcomes, so you can see why something was recommended instead of trusting unexplained AI output.

Signal → Insight → Approval → Mission → Task → Outcome

CIOS records key authentication, configuration, token-lifecycle and workflow-change events. A complete audit trail of every individual read of customer data is not yet available.

SERVICE PROVIDERS

Established providers, named openly.

Google Cloud Auth0 MongoDB Atlas Weaviate Google Gemini Anthropic OpenAI

A detailed sub-processor register is available for security and privacy reviews.

RETENTION, DELETION & INTEGRATIONS

Encryption

Encrypted connections for external traffic and major cloud and AI services; encryption at rest through the underlying providers; private networking for internal services.

Deletion

Data sources, knowledge sources, insights, missions, tasks and connectors can be deleted. Tenant-wide erasure and export workflows are agreed during onboarding.

Integrations

Connections to feedback, ticketing, survey and review platforms use your own credentials. Connector secrets are hidden from user-facing API responses.

Reviewing CIOS for a regulated environment?

We can walk your security, privacy and procurement teams through architecture, data flows, tenant isolation, AI providers, sub-processors and current compliance status.

Request a security review