Skip to main content

    Security

    How we protect your data and the systems that run your Digital Employees.

    Last updated01 July 2026
    Version1.0 draft
    Applies tothe Outcome1.AI service

    Security is foundational to how we build. Our Digital Employees work with the data that runs your business, and protecting it is a first-order responsibility, not an afterthought. This page describes the technical and organisational measures we have in place today to keep your data confidential, available and intact.

    On this page
    1. Our approach to security
    2. Data ownership, privacy and AI
    3. Data residency and hosting
    4. Encryption
    5. Access control and authentication
    6. Tenant and data isolation
    7. Application and infrastructure security
    8. Sub-processors and vendor management
    9. Backups and recovery
    10. Incident response
    11. Data retention and deletion
    12. Reporting a security issue

    01 Our approach to security

    We design for security and privacy from the start, and we apply defence in depth: protection at the network, application, data and access layers, rather than relying on any single control. We collect and process only the data needed to do the job, we keep access to the minimum required, and we hold ourselves to the data-protection commitments in our Data Processing Agreement and Privacy Policy. The measures below reflect what is in place today; our security programme continues to mature as we grow. We are currently below the size thresholds that bring providers into the mandatory scope of the EU NIS2 framework (transposed in Romania by OUG 155/2024), and we build our controls so that customers who are themselves in scope can rely on us within their supply chain.

    Security is part of how work is authorised, executed and reviewed.

    1. Define authority

      Access begins with an identified role, a legitimate need, and only the permissions required for the work.

      Review access controls
    2. Protect information

      Customer information remains within defined boundaries and is protected throughout its working lifecycle.

      Review data protections
    3. Govern action

      Sensitive or consequential actions are constrained by policy, approval, and accountable human decision rights.

      Review action controls
    4. Preserve evidence

      Security-relevant activity leaves reviewable evidence so actions, changes, and interventions can be investigated.

      Review traceability controls
    5. Sustain operations

      Monitoring, backup, recovery, incident handling, and controlled change support continued and recoverable service.

      Review backup and recovery

    See how these controls shape governed digital work in Platform Security.

    ↑ Back to top

    02 Data ownership, privacy and AI

    How we treat your data is itself a security decision, and a few commitments are central to how the product works:

    • We do not train foundation models on your data. Your data is used to operate your Digital Employees, not to train the underlying models.
    • We do not pool or share your data across customers. Each customer's data stays within that customer's environment.
    • You own your data and your Contextual Memory. The data you provide, and the institutional context a Digital Employee learns within your instance, belong to you, as set out in the Data Processing Agreement.

    These commitments are reinforced by purpose limitation and data minimisation: access to Customer Data is limited to the role, workflow and support need for which it is required.

    ↑ Back to top

    03 Data residency and hosting

    Core service processing takes place in the EEA. We host the core of the Service on Microsoft Azure in Germany West Central (Frankfurt), where core compute and storage remain. Foundation-model providers are reached through EU endpoints. Optional voice features may involve processing in the United States under Standard Contractual Clauses. Current sub-processors, their locations and the transfer mechanism that applies to each are listed in Annex 3 of our Data Processing Agreement.

    ↑ Back to top

    04 Encryption

    We encrypt Customer Data in transit and at rest. External traffic uses HTTPS with TLS (version 1.2 or higher), with no plaintext serving, and stored data uses AES-256 encryption. Encryption keys are held separately from Customer Data, access to key-management functions is restricted, and key-lifecycle actions are treated as security-relevant events.

    ↑ Back to top

    05 Access control and authentication

    Access to systems and Customer Data is granted on a least-privilege, need-to-know basis, with individual accounts and multi-factor authentication for administrative access. Access rights are aligned to a person's role and removed promptly when no longer needed or when someone leaves. Permissions are reviewed periodically, and elevated access is limited in time and scope where needed. Administrative and security-relevant actions are written to an append-only, integrity-chained audit log, with the audit event stream retained for 90 days.

    ↑ Back to top

    06 Tenant and data isolation

    Each customer's data is separated through layered controls at the application and data layers. Services use limited roles, customer boundaries are enforced consistently across scoped access, and automated tests verify the boundaries intended to prevent one customer from accessing another customer's data or Contextual Memory.

    ↑ Back to top

    07 Application and infrastructure security

    Changes reach production only after automated build, test and security checks on a protected branch. Release artifacts include a software bill of materials (SBOM) and are verified before deployment. Software components and container images are scanned for vulnerabilities, dependencies are kept current through controlled updates, and services produce structured logs, metrics and traces used to monitor service health, investigate issues and route relevant alerts.

    ↑ Back to top

    08 Sub-processors and vendor management

    We carry out due diligence on the third parties that process data on our behalf before engaging them, and we bind them by contract to data-protection and security obligations consistent with our own. We maintain a current list of these sub-processors, with their locations and the transfer mechanism that applies to each, in Annex 3 of our Data Processing Agreement. Components we host within our own infrastructure are part of our environment and are not third-party sub-processors.

    ↑ Back to top

    09 Backups and recovery

    We use automated daily database backups and additional restore points before high-risk maintenance. Backup health is monitored so failures can be addressed, and recovery procedures are maintained to restore availability of and access to data after an incident. Our approach to service availability is described in the Service Level Agreement.

    ↑ Back to top

    10 Incident response

    Security signals are monitored and relevant incident classes are routed for response. We maintain a process to detect, escalate and respond to security incidents. If a personal data breach affects your data, we will notify you without undue delay, give you the information you need to meet your own obligations, and work with you to contain and remediate the issue, in line with our Data Processing Agreement and applicable law.

    ↑ Back to top

    11 Data retention and deletion

    We operate on the basis of no retention of your data after our contract ends. When the contract ends, we make your data available for export through a download link available for 30 days, consistent with your right to data portability and erasure, and you can request complete deletion at your discretion. The Contextual Memory learned within your instance is treated as your data for these purposes.

    ↑ Back to top

    12 Reporting a security issue

    If you believe you have found a security vulnerability in our Service, we want to hear from you. Please see our Vulnerability Disclosure Policy for how to report it, or contact us directly:

    Outcome1 SRL · Security

    Email: security@outcome1.ai