Security & Data
PSV can build the Company Brain and its workflows inside the environment you already control. Where the work runs is a deployment decision you make, not a constraint we impose.
Deployment
Every engagement is designed for review. Where the work runs is scoped to your policy before anything gets built.
The default, supervised by you
PSV provisions and operates the environment, with per-client data isolation, AES-256 at rest, and TLS 1.3 in transit. The work lands where your team already looks, and you approve the output. The right fit for firms without an infrastructure mandate.
Provisioned for your firm, run by PSV
A turnkey environment set up for your firm alone and managed by PSV, designed to sit behind your SSO. Institutional controls without your team running infrastructure: access scoped to the least it needs, every action logged.
Inside the tenancy you already govern
For data residency or regulator-mandated isolation, we can deploy inside your own AWS, GCP, or Azure account, your Microsoft 365 world, or on-premise. Your VPC, behind your SSO, with audit logging configured to your standards. We scope the architecture to your compliance envelope before we build.
The split
PSV operates the layer that makes the work run. What the work runs on stays on your side of the line.
PSV control plane
The machinery that makes the system run: how workflows are configured, what shape the records take, and how everything is monitored and deployed.
Your data plane
The substance the machinery runs on. It lives in the deployment configuration you chose, under your access controls.
Where technically appropriate, raw documents stay in your source systems. The Brain stores structured intelligence and provenance references, pointers to the exact page a number came from, rather than a second copy of your file room.
Controls
Six controls your IT and compliance reviewers can check, stated the way they will ask about them.
An agent runs against the systems, folders, and actions you approve, and nothing else. Access is permissioned per tool, scoped to the least it needs, and revocable.
Deployments are designed to sit behind your single sign-on, so your identity provider governs who can reach the system.
Nothing you provide trains a public or shared model. For regulated workloads we use providers with zero-retention agreements.
Output cites the source document it came from, so a reviewer checks the work against the page instead of taking it on faith.
Nothing the system observes becomes firm knowledge on its own. A person reviews and approves it first, and people stay the authority.
Every read and write is logged: what ran, what it read, and what it produced, available to your reviewers.
Standards
The list your reviewers will ask for, with the status stated plainly. Grey means we are working on it and have not finished.
Coverage
Independent attestation that our security controls operate effectively over time, not just on paper.
Documentation
Current controls documentation available today. Report shared under NDA once the examination closes.
Coverage
EU and UK data protection requirements met, with the Article 6 legal basis documented for every category of processing.
Documentation
Privacy notice published. Data processing agreement on request.
Coverage
California consumer rights honored, including access, deletion, correction, and opt-out of sale or sharing.
Documentation
Privacy documentation published, with a named contact for requests.
Coverage
For regulated workloads we use providers under zero-retention agreements. Nothing you give us trains a public or shared model.
Documentation
Provider terms and our data-handling memo shared during vendor review.
Coverage
The standard vendor questionnaire, completed and kept current, plus your own addendum signed on request.
Documentation
Completed questionnaire shared on request.
Coverage
PSV's MCP connector, being prepared for listing in Anthropic's official Claude connector directory.
Documentation
Public directory listing once approved.
SOC and GDPR ready, built to pass your audit. We are pursuing SOC 2 Type II and do not claim certifications we do not hold. You will not find a certification badge on this page for a standard we have not completed. Controls documentation, a completed SIG Lite questionnaire, and signed security addenda are available on request.
For institutional firms
We write the security memo, complete your vendor questionnaire, and get on the call with your reviewers. Our job is not done until you pass your own audit.
Explore EnterpriseThe detailed answers
How we handle data, GDPR and CCPA, PII in prompts, and regulated deployments, answered directly.
Read the security answersGovernance notes · PSV newsletter
Deployment configurations, the access and approval questions that come up in vendor review, and how firms document AI use for their own auditors. Written for the people who have to sign off.
No spam. Unsubscribe in one click.
Next step
Ten minutes. An honest read on where you stand, the highest-value opportunities, and which engagement fits, if any.