Skip to main content
Security & data flow

What leaves the building, under what terms, with what audit trail.

If you're the person who has to sign off on the data, this page is for you. Here's how we handle it — and where the honest limits are.

How the data flows

You see the diagram first, not last.

Your data is processed through Anthropic's API. We document the full data flow for your specific implementation before any production data touches the system — what's sent, where, why, and who approved it.

01

Your systems

CRM, call recorder, support tool, Slack, Drive. Read-only access, provisioned with your IT team.

02

Processing

Sent to Anthropic's API under the enterprise terms below. No training on your data.

03

Draft to operator

A structured draft returns to your operator. Nothing is sent externally yet.

04

Human approval

Your operator approves, edits, or rejects. Only then does anything happen — and it's logged.

Per-engagement data-flow diagram — produced during scoping
The platform terms

Precise about what's true of the platform.

At the enterprise tier of Anthropic's API, there is no training on your data, and a data processing agreement is in place. Anthropic maintains SOC 2 Type II for its API. EU data residency options are available at the enterprise tier — not on consumer plans, and this is true across the major AI providers, not unique to one.

To be precise: these are terms of the underlying platform we build on. We'll point you to the current, authoritative versions rather than paraphrase them into something we can't stand behind.

Governance we build

The layer that's ours, on top of the platform.

Approval

A human approval step on every external action. Draft, then review. Nothing autonomous.

Audit trail

A record of what was approved and by whom — searchable, exportable for regulatory review.

Documented flow

The data-flow diagram above. It maps to the EU AI Act's requirements for high-risk systems.

The honest limit.

If you have a hard requirement that data cannot leave a specific environment, that changes the architecture — and we need to discuss it before we scope anything, not after. We won't claim a residency or a guarantee we can't demonstrate for your situation. If we can't close the gap, we'll say so.

Questions about your specific situation? Book a free call