Skip to main content
FAQ  /  Security, Privacy & Trust
FAQ · Security, Privacy & Trust

Security, Privacy & Trust

Access control, data protection, tenant isolation and accountable AI.

AskAI and AI Synthesis
Could someone use AskAI to see numbers they're not supposed to?
For IT & data

No. AskAI resolves the user's role, organisation, object access and underlying data visibility before it assembles evidence, and users can only question the objects and data they're authorised to see. The conversation never expands a person's permissions.

Connected Data and Federated Evidence
How do you keep source permissions and network boundaries intact through all this?
For IT & data

Source, platform and AI controls are applied throughout the evidence path — the integration design respects the customer's identity, source permissions, data restrictions, network boundaries and hosting model, rather than bypassing them.

Decisions, Actions and Management Continuity
Can we keep sensitive deliberation private while still sharing the outcome?
For IT & data

Yes. Collaboration follows the same security model as the surrounding experience — object access, data visibility, record visibility and detail separation — so sensitive deliberation can stay restricted while approved summaries are shared appropriately, aligned to functional-area controls.

Security, Privacy and Trust
How do you make sure people only see what they're allowed to?
For IT & data

Through least-necessary access applied across three layers together — the application (which experiences), the business object (which commitments, measures, value streams), and the underlying data (granular row/entity restrictions) — rather than relying on a single page-level permission. Users are authorised before business and data context is resolved.

What actually happens to our data when the AI is involved — does it leave our environment?
For IT & data

Structured analysis is designed to execute within the customer-controlled environment rather than sending readable records to an AI provider. Where limited context is required, business keys are encrypted or tokenised and numeric values obfuscated, then restored inside your trusted boundary before presentation — so raw customer data isn't shared with the AI provider.

How are customers kept isolated from one another?
For IT & data

Customer-specific boundaries are applied explicitly across application services, data stores, storage, integration credentials, caches, logs and administrative access — with the isolation model aligned to your deployment, security and regulatory requirements.

How do you handle data retention, deletion and privacy obligations?
For IT & data

Privacy is implemented through product configuration, deployment controls, operating procedures and customer instructions, with a defined lifecycle: define purpose, minimise data, authorise access, process securely, retain intentionally, delete or return, and demonstrate — with applicable legal, contractual, geographic and data-category requirements mapped to your environment.

If something is questioned later, what audit trail exists?
For IT & data

Auditability covers user and administrative activity, business-model and access history, source/lineage/freshness behind a reading, and the discussion/decision/action history — so you can explain who accessed what, how a narrative or outcome was derived, why an intervention was required and what result followed.

Who's responsible for what — you or us?
For IT & data

Security is shared, not handed entirely to either side. VibrantAI operates and maintains the documented platform, analytical, integration and AI controls within the service boundary; the customer governs users, sources, business meaning and authorised use per its own access, privacy, risk and records-management requirements. A control-and-responsibility matrix makes the split explicit for enterprise due diligence.

EnvisionAI
Does using AI mean our data goes out to a model provider?
For IT & data

No. Structured analysis executes within the customer-controlled environment; where limited AI context is needed, business keys are encrypted or tokenised and values obfuscated, then restored inside your boundary. Generated SQL and Python run through approved analytical services and customer-specific execution controls, and AI access never expands a user's underlying permissions.

Still have questions?

Talk to us about your goals and we'll show how Vibrant Outcomes applies to them.

Schedule a briefing →