Security and control

For the person deciding what Athren may read, what it may write and where the delivery record lives.

Zendesk
HubSpot
Gmail

Reply to Rijnveld about the weekend.

A scene playing on a loop. Somebody says: Reply to Rijnveld about the weekend.. The run reaches zendesk, which returns read · 1 escalation; then hubspot, which returns read · owner Nadia; then gmail, which returns write · held, not sent. The reads go through. The write stops there, and nothing leaves until a person approves it.
Where does our data sit?
Inside the European Union: your documents, the index built from them, and the model calls made against them. The same software runs in your own environment.
Can it write without us?
A connection can be read-only, and stay read-only until it has earned more. When you allow a write, it is proposed in full and nothing goes out until a person approves it.
What does a run leave?
One entry in the audit chain. Each entry signs the one before it, so an edit after the fact breaks the chain.
How do we get it deleted?
Ask for erasure, and the same chain records what was held and what was removed.

One run, stop by stop

One run, drawn inside a single boundary: a request arriving in your tenant, retrieval over your own index, the model call against European inference, the write that happens once a person approves it, and the entry left in your ledger. Every stop is inside the same European deployment.

Nothing crosses the Atlantic

Three documents you will ask for

None of the three is written yet.

  • Data processing agreement
  • Subprocessor list
  • Deletion procedure

Finish the client call with the work already mapped.

Send one recent client meeting. Leave with the actions, follow-ups and exceptions a person can approve.