Security & Data
PSV can build the Company Brain and its workflows inside the environment you already control. Where the work runs is a deployment decision you make, not a constraint we impose.
Deployment
Every engagement is designed for review. Where the work runs is scoped to your policy before anything gets built.
The default, supervised by you
PSV provisions and operates the environment, with per-client data isolation, AES-256 at rest, and TLS 1.3 in transit. The work lands where your team already looks, and you approve the output. The right fit for firms without an infrastructure mandate.
Provisioned for your firm, run by PSV
A turnkey environment set up for your firm alone and managed by PSV, designed to sit behind your SSO. Institutional controls without your team running infrastructure: access scoped to the least it needs, every action logged.
Inside the tenancy you already govern
For data residency or regulator-mandated isolation, we can deploy inside your own AWS, GCP, or Azure account, your Microsoft 365 world, or on-premise. Your VPC, behind your SSO, with audit logging configured to your standards. We scope the architecture to your compliance envelope before we build.
The split
PSV operates the layer that makes the work run. What the work runs on stays on your side of the line.
PSV control plane
The machinery that makes the system run: how workflows are configured, what shape the records take, and how everything is monitored and deployed.
Your data plane
The substance the machinery runs on. It lives in the deployment configuration you chose, under your access controls.
Where technically appropriate, raw documents stay in your source systems. The Brain stores structured intelligence and provenance references, pointers to the exact page a number came from, rather than a second copy of your file room.
Controls
Six controls your IT and compliance reviewers can check, stated the way they will ask about them.
An agent runs against the systems, folders, and actions you approve, and nothing else. Access is permissioned per tool, scoped to the least it needs, and revocable.
Deployments are designed to sit behind your single sign-on, so your identity provider governs who can reach the system.
Nothing you provide trains a public or shared model. For regulated workloads we use providers with zero-retention agreements.
Output cites the source document it came from, so a reviewer checks the work against the page instead of taking it on faith.
Nothing the system observes becomes firm knowledge on its own. A person reviews and approves it first, and people stay the authority.
Every read and write is logged: what ran, what it read, and what it produced, available to your reviewers.
SOC and GDPR ready, built to pass your audit. We are pursuing SOC 2 Type II and do not claim certifications we do not hold. Controls documentation, a completed SIG Lite questionnaire, and signed security addenda are available on request.
For institutional firms
We write the security memo, complete your vendor questionnaire, and get on the call with your reviewers. Our job is not done until you pass your own audit.
Explore EnterpriseThe detailed answers
How we handle data, GDPR and CCPA, PII in prompts, and regulated deployments, answered directly.
Read the security answersGovernance notes · PSV newsletter
Deployment configurations, the access and approval questions that come up in vendor review, and how firms document AI use for their own auditors. Written for the people who have to sign off.
No spam. Unsubscribe in one click.
Next step
Ten minutes. An honest read on where you stand, the highest-value opportunities, and which engagement fits, if any.