Founder letter: governed execution

Security and assurance

Control is part of the product.

ENAI is designed for revenue work that touches customer relationships, private context, and company reputation. Security and governance are reviewed as one system.

Governance model

The system should know what it may do, why it may do it, and when to stop.

Authority is explicit

Customer-defined rules determine what ENAI can research, prepare, approve, send, or escalate.

Actions remain explainable

Revenue work is tied back to source context, workflow rules, and the human handoff path.

Customer boundaries matter

Workspace access and tenant controls are designed to keep customer context separated and permissioned.

Judgment has an owner

Sensitive accounts, unsupported claims, and exceptions can be routed to a person before action is taken.

Data safeguards

Clear commitments, stated precisely.

Security language should be reviewable, not ornamental. Deployment-specific requirements are documented with the customer before ENAI is given authority.

Encrypted data handling

Customer data is protected in transit and at rest using industry-standard encryption controls.

Controlled access

Access is limited by role and operational need, with enterprise identity and audit requirements addressed during deployment.

No model training on customer data

Customer data is not used to train generalized AI models. Retention and deletion terms are agreed as part of deployment.

Assurance roadmap

No badge before the evidence.

SOC 2 Type II

Readiness programme in progress

Certification is not currently claimed

ISO 27001

Control mapping on the assurance roadmap

Certification is not currently claimed

GDPR and CCPA

Data protection and contract review

Regulatory alignment, not a certification badge

Enterprise review

Review the controls against your requirements.

Start a security review