Security and assurance
Control is part of the product.
ENAI is designed for revenue work that touches customer relationships, private context, and company reputation. Security and governance are reviewed as one system.
Governance model
The system should know what it may do, why it may do it, and when to stop.
Authority is explicit
Customer-defined rules determine what ENAI can research, prepare, approve, send, or escalate.
Actions remain explainable
Revenue work is tied back to source context, workflow rules, and the human handoff path.
Customer boundaries matter
Workspace access and tenant controls are designed to keep customer context separated and permissioned.
Judgment has an owner
Sensitive accounts, unsupported claims, and exceptions can be routed to a person before action is taken.
Data safeguards
Clear commitments, stated precisely.
Security language should be reviewable, not ornamental. Deployment-specific requirements are documented with the customer before ENAI is given authority.
Encrypted data handling
Customer data is protected in transit and at rest using industry-standard encryption controls.
Controlled access
Access is limited by role and operational need, with enterprise identity and audit requirements addressed during deployment.
No model training on customer data
Customer data is not used to train generalized AI models. Retention and deletion terms are agreed as part of deployment.
Assurance roadmap
No badge before the evidence.
SOC 2 Type II
Readiness programme in progress
Certification is not currently claimed
ISO 27001
Control mapping on the assurance roadmap
Certification is not currently claimed
GDPR and CCPA
Data protection and contract review
Regulatory alignment, not a certification badge
Enterprise review