Skip to content

Security, privacy and governance

Since 0.4.0

Ajutant is a governed AI platform. Governance is not a feature bolted on the side, it is what makes AI safe to deploy across an enterprise: control over where data goes, who can do what, what the models are allowed to say, and a record of everything that happened.

This page is for a security or procurement reviewer. It answers the standard enterprise AI security questions in one place, and links to the detailed article behind each answer so you can verify the specifics.

You choose the model providers, the regions, and the deployment style. Ajutant runs on your chosen providers (including Azure OpenAI, and other supported providers), and each model is deployed to a region you select, so data residency is a configuration you control rather than a default you inherit. See models and providers for how models, providers, regions and deployments are registered and mapped.

Documents and conversations are classified, governed by a lawful basis, and subject to retention rules that an administrator sets. See data governance and GDPR for classification, lawful basis, clearance and retention.

Input and output guardrails run on the platform and can be tuned per assistant, including detection and redaction of personal data before it reaches a model or a reader. See configure guardrails and PII redaction.

Access is role-based. Roles are built from fine-grained capabilities, users belong to teams, and what a person can see and do follows from the roles they hold. See users, teams and roles and the reference on roles and capabilities.

Actions across the platform are recorded so an administrator can review what happened, trace an answer, and investigate failures. See monitoring and diagnostics.

Publishing can be gated behind approval, and an administrator can stop an assistant or the platform quickly when something looks wrong. See approval and the kill switch.

Ajutant provides the tooling to run AI on a lawful basis: classification, clearance, retention, and the governance controls that sit around them. See data governance and GDPR.

The controls above (provider and region choice, RBAC, guardrails, audit, approval and the kill switch, and GDPR tooling) are the building blocks a security review looks for. For how these controls fit together from sign-in to answer, see the governance model. Formal certification claims are verified by our security and legal teams before they appear here, so ask your Ajutant contact for the current attestations and reports relevant to your review.