Security / governance

Powerful enough to help.
Specific enough to trust.

Security is part of the operating layer: clear workspace boundaries, role-aware access, approvals, traceable records, and transparent AI data handling.

Controls that follow responsibility

Governance should be visible in the workflow.

We describe the controls we intend to provide and publish precise details as they become available. CBSai does not claim certifications before they apply.

01

Workspace isolation

Organizational boundaries and operating context stay clearly separated.

02

Roles & permissions

Information and actions follow the responsibility assigned to each role.

03

Approvals

Recommendations can remain reviewable before a consequential action proceeds.

04

Audit records

Important changes and decisions should leave a trace that teams can inspect.

05

Data handling

AI behavior and data pathways should be clear enough to discuss with your team.

06

Operational resilience

Backups, access recovery, incident response, and retention belong in the implementation conversation.

Published controls

What is true today,
stated plainly.

Enough to start a security questionnaire without waiting for a call. Everything below is a fact about how CBSai is already built. Where we have not finished something, it says so rather than being softened.

HOSTING

Google Cloud & Firebase

CBSai is hosted end to end on Google Cloud Platform and Firebase. Data at rest sits within Google Cloud’s managed storage and its platform-level encryption.

TRANSPORT

TLS in transit

All traffic between clients and CBSai is encrypted in transit over TLS.

ISOLATION

Multi-tenant, workspace isolated

Each customer operates in an isolated workspace. Tenant isolation is enforced at the data layer, not by interface filtering.

ACCESS

Role-based access control

RBAC governs what every user — and every agent acting for that user — can read or change. An agent cannot surface a record its requesting user is not entitled to see.

IDENTITY

SSO, SAML and SCIM

Single sign-on with SAML, and SCIM for automated user provisioning and de-provisioning, are built. For a platform holding HR, payroll and finance data we treat identity federation as a requirement, not an upsell.

PAYMENTS

Stripe

Payments are processed by Stripe. CBSai does not store raw card data.

Subprocessors

Who else touches the data

01Google CloudApplication hosting, compute and data storage
02FirebaseApplication platform services and authentication
03StripePayment processing and billing

Not yet published, and we will not imply otherwise: a completed SOC 2 or ISO 27001 certification, a formal backup and disaster-recovery schedule, a stated breach-notification window, and confirmed data-residency options. These are being documented; we will publish dates and specifics when they are real, and will answer them directly in writing during a security review in the meantime. A DPA is available on request.

AI data handling

Artemis Shadow learns your business.
Inside your boundary.

Artemis Shadow trains on your workspace from day one so the intelligence reflects how your operation actually runs. That only works if the boundary around it is unambiguous, so here it is in plain terms.

SCOPE

Your workspace only

Shadow learns within your workspace. Your operating data is not pooled with other customers and is not used to train a shared model that another organisation benefits from.

CONTROL

Permissions still apply

Agents inherit the same role-aware permissions as the people they work for. An agent cannot surface a record the requesting user is not entitled to see.

AUTHORITY

A person still decides

Consequential actions require human approval. The recommendation, the records behind it and the decision are all retained so the reasoning can be reviewed later.

We will confirm the precise technical controls, retention periods and regional processing arrangements in writing during a security review, rather than implying certifications we do not yet hold.

A precise conversation

Bring the questions that matter to your operation.

We can walk through workspace structure, authentication, permissions, integrations, data retention, AI usage, and the evidence you need before adoption.

How is tenant data separated?What can an assistant access?Where are approvals required?What is logged and retained?How does implementation change our controls?
Security documentation

Specific answers are better than broad assurances.

Request a walkthrough and we will align the conversation to your security, compliance, and procurement process.

Request a security conversation