Security, privacy and governance
Ajutant is a governed AI platform. Governance is not a feature bolted on the side, it is what makes AI safe to deploy across an enterprise: control over where data goes, who can do what, what the models are allowed to say, and a record of everything that happened.
This page is for a security or procurement reviewer. It answers the standard enterprise AI security questions in one place, and links to the detailed article behind each answer so you can verify the specifics.
Where your data goes
Section titled “Where your data goes”You choose the model providers, the regions, and the deployment style. Ajutant runs on your chosen providers (including Azure OpenAI, and other supported providers), and each model is deployed to a region you select, so data residency is a configuration you control rather than a default you inherit. See models and providers for how models, providers, regions and deployments are registered and mapped.
Data handling and retention
Section titled “Data handling and retention”Documents and conversations are classified, governed by a lawful basis, and subject to retention rules that an administrator sets. See data governance and GDPR for classification, lawful basis, clearance and retention.
PII redaction and guardrails
Section titled “PII redaction and guardrails”Input and output guardrails run on the platform and can be tuned per assistant, including detection and redaction of personal data before it reaches a model or a reader. See configure guardrails and PII redaction.
Access control: roles, teams and RBAC
Section titled “Access control: roles, teams and RBAC”Access is role-based. Roles are built from fine-grained capabilities, users belong to teams, and what a person can see and do follows from the roles they hold. See users, teams and roles and the reference on roles and capabilities.
Audit logging
Section titled “Audit logging”Actions across the platform are recorded so an administrator can review what happened, trace an answer, and investigate failures. See monitoring and diagnostics.
Approval and the kill switch
Section titled “Approval and the kill switch”Publishing can be gated behind approval, and an administrator can stop an assistant or the platform quickly when something looks wrong. See approval and the kill switch.
GDPR and lawful basis
Section titled “GDPR and lawful basis”Ajutant provides the tooling to run AI on a lawful basis: classification, clearance, retention, and the governance controls that sit around them. See data governance and GDPR.
Compliance posture
Section titled “Compliance posture”The controls above (provider and region choice, RBAC, guardrails, audit, approval and the kill switch, and GDPR tooling) are the building blocks a security review looks for. For how these controls fit together from sign-in to answer, see the governance model. Formal certification claims are verified by our security and legal teams before they appear here, so ask your Ajutant contact for the current attestations and reports relevant to your review.