Workspace isolation
Organizational boundaries and operating context stay clearly separated.
Security is part of the operating layer: clear workspace boundaries, role-aware access, approvals, traceable records, and transparent AI data handling.
We describe the controls we intend to provide and publish precise details as they become available. CBSai does not claim certifications before they apply.
Organizational boundaries and operating context stay clearly separated.
Information and actions follow the responsibility assigned to each role.
Recommendations can remain reviewable before a consequential action proceeds.
Important changes and decisions should leave a trace that teams can inspect.
AI behavior and data pathways should be clear enough to discuss with your team.
Backups, access recovery, incident response, and retention belong in the implementation conversation.
Enough to start a security questionnaire without waiting for a call. Everything below is a fact about how CBSai is already built. Where we have not finished something, it says so rather than being softened.
CBSai is hosted end to end on Google Cloud Platform and Firebase. Data at rest sits within Google Cloud’s managed storage and its platform-level encryption.
All traffic between clients and CBSai is encrypted in transit over TLS.
Each customer operates in an isolated workspace. Tenant isolation is enforced at the data layer, not by interface filtering.
RBAC governs what every user — and every agent acting for that user — can read or change. An agent cannot surface a record its requesting user is not entitled to see.
Single sign-on with SAML, and SCIM for automated user provisioning and de-provisioning, are built. For a platform holding HR, payroll and finance data we treat identity federation as a requirement, not an upsell.
Payments are processed by Stripe. CBSai does not store raw card data.
Not yet published, and we will not imply otherwise: a completed SOC 2 or ISO 27001 certification, a formal backup and disaster-recovery schedule, a stated breach-notification window, and confirmed data-residency options. These are being documented; we will publish dates and specifics when they are real, and will answer them directly in writing during a security review in the meantime. A DPA is available on request.
Artemis Shadow trains on your workspace from day one so the intelligence reflects how your operation actually runs. That only works if the boundary around it is unambiguous, so here it is in plain terms.
Shadow learns within your workspace. Your operating data is not pooled with other customers and is not used to train a shared model that another organisation benefits from.
Agents inherit the same role-aware permissions as the people they work for. An agent cannot surface a record the requesting user is not entitled to see.
Consequential actions require human approval. The recommendation, the records behind it and the decision are all retained so the reasoning can be reviewed later.
We will confirm the precise technical controls, retention periods and regional processing arrangements in writing during a security review, rather than implying certifications we do not yet hold.
We can walk through workspace structure, authentication, permissions, integrations, data retention, AI usage, and the evidence you need before adoption.
Request a walkthrough and we will align the conversation to your security, compliance, and procurement process.