Security & Data
Your data does not have to leave your environment.
PSV can build the Company Brain and its workflows inside the environment you already control. Where the work runs is a deployment decision you make, not a constraint we impose.
Deployment
Three configurations, one decision that stays yours.
Every engagement is designed for review. Where the work runs is scoped to your policy before anything gets built.
- 01
PSV-managed cloud
The default, supervised by you
PSV provisions and operates the environment, with per-client data isolation, AES-256 at rest, and TLS 1.3 in transit. The work lands where your team already looks, and you approve the output. The right fit for firms without an infrastructure mandate.
- 02
Dedicated environment
Provisioned for your firm, run by PSV
A turnkey environment set up for your firm alone and managed by PSV, designed to sit behind your SSO. Institutional controls without your team running infrastructure: access scoped to the least it needs, every action logged.
- 03
Your cloud or VPC
Inside the tenancy you already govern
For data residency or regulator-mandated isolation, we can deploy inside your own AWS, GCP, or Azure account, your Microsoft 365 world, or on-premise. Your VPC, behind your SSO, with audit logging configured to your standards. We scope the architecture to your compliance envelope before we build.
The split
A clean line between the system and what it knows.
PSV operates the layer that makes the work run. What the work runs on stays on your side of the line.
PSV control plane
What we operate
- Configuration
- Workflow schemas
- Skills
- Monitoring
- Deployment
The machinery that makes the system run: how workflows are configured, what shape the records take, and how everything is monitored and deployed.
Your data plane
What stays yours
- Documents
- Company data
- Brain records
- Decisions
- Relationships
The substance the machinery runs on. It lives in the deployment configuration you chose, under your access controls.
Where technically appropriate, raw documents stay in your source systems. The Brain stores structured intelligence and provenance references, pointers to the exact page a number came from, rather than a second copy of your file room.
Controls
Designed for the security review, not patched in after it.
Six controls your IT and compliance reviewers can check, stated the way they will ask about them.
- 01
Scoped access
An agent runs against the systems, folders, and actions you approve, and nothing else. Access is permissioned per tool, scoped to the least it needs, and revocable.
- 02
Your SSO in front
Deployments are designed to sit behind your single sign-on, so your identity provider governs who can reach the system.
- 03
No training on your data
Nothing you provide trains a public or shared model. For regulated workloads we use providers with zero-retention agreements.
- 04
Every number traced
Output cites the source document it came from, so a reviewer checks the work against the page instead of taking it on faith.
- 05
Humans approve knowledge
Nothing the system observes becomes firm knowledge on its own. A person reviews and approves it first, and people stay the authority.
- 06
A reviewable trail
Every read and write is logged: what ran, what it read, and what it produced, available to your reviewers.
Standards
Where we stand on each one, including the ones still open.
The list your reviewers will ask for, with the status stated plainly. Grey means we are working on it and have not finished.
SOC 2 Type II
In progressCoverage
Independent attestation that our security controls operate effectively over time, not just on paper.
Documentation
Current controls documentation available today. Report shared under NDA once the examination closes.
GDPR
AlignedCoverage
EU and UK data protection requirements met, with the Article 6 legal basis documented for every category of processing.
Documentation
Privacy notice published. Data processing agreement on request.
CCPA and CPRA
AlignedCoverage
California consumer rights honored, including access, deletion, correction, and opt-out of sale or sharing.
Documentation
Privacy documentation published, with a named contact for requests.
Zero-retention model providers
In placeCoverage
For regulated workloads we use providers under zero-retention agreements. Nothing you give us trains a public or shared model.
Documentation
Provider terms and our data-handling memo shared during vendor review.
SIG Lite
AvailableCoverage
The standard vendor questionnaire, completed and kept current, plus your own addendum signed on request.
Documentation
Completed questionnaire shared on request.
Claude connector directory
In progressCoverage
PSV's MCP connector, being prepared for listing in Anthropic's official Claude connector directory.
Documentation
Public directory listing once approved.
SOC and GDPR ready, built to pass your audit. We are pursuing SOC 2 Type II and do not claim certifications we do not hold. You will not find a certification badge on this page for a standard we have not completed. Controls documentation, a completed SIG Lite questionnaire, and signed security addenda are available on request.
For institutional firms
Enterprise deployments
We write the security memo, complete your vendor questionnaire, and get on the call with your reviewers. Our job is not done until you pass your own audit.
Explore EnterpriseThe detailed answers
Security & compliance FAQ
How we handle data, GDPR and CCPA, PII in prompts, and regulated deployments, answered directly.
Read the security answersGovernance notes · PSV newsletter
Governance and deployment notes for reviewers.
Deployment configurations, the access and approval questions that come up in vendor review, and how firms document AI use for their own auditors. Written for the people who have to sign off.
No spam. Unsubscribe in one click.
Next step
See where AI creates leverage across your firm.
Ten minutes. An honest read on where you stand, the highest-value opportunities, and which engagement fits, if any.