The Artificial Organisation
Log inBook a discovery callBook a call
Back to home
Trust and security

Your inbox, your books, your customers. Handing them over is a big ask.

We know, because we handed over our own business first. So TAO is built like the thing holding it. Every client on their own isolated database. Two-factor sign-in on every account. Connections through each tool’s official access, with only the permissions the job needs, which you can see and revoke at any time. A person approves everything Andy sends or changes, and every action is on the record. SOC 2 is in progress, and we say so until it is done.

How your business is held

Five rings around it, inside out.

What Andy can and cannot do

The assistant is capable on purpose, and limited on purpose.

Andy canRead your record, so it answers from the real picture.Draft, propose and notice, inside every module.Act only through the connections you have approved.
Andy cannotSend anything without a person saying yes.Change a record without approval.See any other client’s business, ever.Train anything for anyone else on your data.

Every action, on the record

A slice of a day from the audit trail: who did what, when, and who approved it.

SOC 2, in progress

We are working through SOC 2 with an external assessor. Until it is complete we say in progress, not certified, because that is what it is.

In progressAsk us where it is up to on the call. We will tell you plainly.

For your IT person

The short version, in their language.

Isolated dataOne database per client. No shared store, no cross-tenant queries.
Sessions and tokensServer-owned sessions. Provider tokens encrypted at rest, never sent to the browser.
AccessTwo-factor sign-in on every account. Roles per person. Every provider scope listed and revocable.
Backups and auditRegular backups, and an audit log of every action across modules.
Built like the thing holding our own business. Because it is.
How we think about security

Questions people ask about security

Where is our data and who can see it?

Every client sits on its own isolated database on restricted-access secure servers. There is no shared database between clients. Inside your workspace, each person sees what their role and permissions allow, and Andy respects the same permissions.

Are you SOC 2 certified?

SOC 2 is in progress with an external assessor. In the meantime every account has two-factor sign-in, every client has an isolated database, servers are restricted-access and every action is logged. The security page has the detail.

What about privacy and data processing agreements?

Our privacy policy sets out what is collected and why, and a data processing agreement is available for every client. Both are public on this site.

One conversation about how your business works.

Half an hour with the people who would build it. Then a proposal for exactly what TAO should take off your plate.