Skip to main content

Security & Data

Your data does not have to leave your environment.

PSV can build the Company Brain and its workflows inside the environment you already control. Where the work runs is a deployment decision you make, not a constraint we impose.

Deployment

Three configurations, one decision that stays yours.

Every engagement is designed for review. Where the work runs is scoped to your policy before anything gets built.

  1. 01

    PSV-managed cloud

    The default, supervised by you

    PSV provisions and operates the environment, with per-client data isolation, AES-256 at rest, and TLS 1.3 in transit. The work lands where your team already looks, and you approve the output. The right fit for firms without an infrastructure mandate.

  2. 02

    Dedicated environment

    Provisioned for your firm, run by PSV

    A turnkey environment set up for your firm alone and managed by PSV, designed to sit behind your SSO. Institutional controls without your team running infrastructure: access scoped to the least it needs, every action logged.

  3. 03

    Your cloud or VPC

    Inside the tenancy you already govern

    For data residency or regulator-mandated isolation, we can deploy inside your own AWS, GCP, or Azure account, your Microsoft 365 world, or on-premise. Your VPC, behind your SSO, with audit logging configured to your standards. We scope the architecture to your compliance envelope before we build.

The split

A clean line between the system and what it knows.

PSV operates the layer that makes the work run. What the work runs on stays on your side of the line.

PSV control plane

What we operate

  • Configuration
  • Workflow schemas
  • Skills
  • Monitoring
  • Deployment

The machinery that makes the system run: how workflows are configured, what shape the records take, and how everything is monitored and deployed.

Your data plane

What stays yours

  • Documents
  • Company data
  • Brain records
  • Decisions
  • Relationships

The substance the machinery runs on. It lives in the deployment configuration you chose, under your access controls.

Where technically appropriate, raw documents stay in your source systems. The Brain stores structured intelligence and provenance references, pointers to the exact page a number came from, rather than a second copy of your file room.

Controls

Designed for the security review, not patched in after it.

Six controls your IT and compliance reviewers can check, stated the way they will ask about them.

  1. 01

    Scoped access

    An agent runs against the systems, folders, and actions you approve, and nothing else. Access is permissioned per tool, scoped to the least it needs, and revocable.

  2. 02

    Your SSO in front

    Deployments are designed to sit behind your single sign-on, so your identity provider governs who can reach the system.

  3. 03

    No training on your data

    Nothing you provide trains a public or shared model. For regulated workloads we use providers with zero-retention agreements.

  4. 04

    Every number traced

    Output cites the source document it came from, so a reviewer checks the work against the page instead of taking it on faith.

  5. 05

    Humans approve knowledge

    Nothing the system observes becomes firm knowledge on its own. A person reviews and approves it first, and people stay the authority.

  6. 06

    A reviewable trail

    Every read and write is logged: what ran, what it read, and what it produced, available to your reviewers.

Standards

Where we stand on each one, including the ones still open.

The list your reviewers will ask for, with the status stated plainly. Grey means we are working on it and have not finished.

  • SOC 2 Type II

    In progress

    Coverage

    Independent attestation that our security controls operate effectively over time, not just on paper.

    Documentation

    Current controls documentation available today. Report shared under NDA once the examination closes.

  • GDPR

    Aligned

    Coverage

    EU and UK data protection requirements met, with the Article 6 legal basis documented for every category of processing.

    Documentation

    Privacy notice published. Data processing agreement on request.

  • CCPA and CPRA

    Aligned

    Coverage

    California consumer rights honored, including access, deletion, correction, and opt-out of sale or sharing.

    Documentation

    Privacy documentation published, with a named contact for requests.

  • Zero-retention model providers

    In place

    Coverage

    For regulated workloads we use providers under zero-retention agreements. Nothing you give us trains a public or shared model.

    Documentation

    Provider terms and our data-handling memo shared during vendor review.

  • SIG Lite

    Available

    Coverage

    The standard vendor questionnaire, completed and kept current, plus your own addendum signed on request.

    Documentation

    Completed questionnaire shared on request.

  • Claude connector directory

    In progress

    Coverage

    PSV's MCP connector, being prepared for listing in Anthropic's official Claude connector directory.

    Documentation

    Public directory listing once approved.

SOC and GDPR ready, built to pass your audit. We are pursuing SOC 2 Type II and do not claim certifications we do not hold. You will not find a certification badge on this page for a standard we have not completed. Controls documentation, a completed SIG Lite questionnaire, and signed security addenda are available on request.

Governance notes · PSV newsletter

Governance and deployment notes for reviewers.

Deployment configurations, the access and approval questions that come up in vendor review, and how firms document AI use for their own auditors. Written for the people who have to sign off.

No spam. Unsubscribe in one click.

Next step

See where AI creates leverage across your firm.

Ten minutes. An honest read on where you stand, the highest-value opportunities, and which engagement fits, if any.