Skip to main content
Security, Privacy and Trust

Enterprise intelligence built around governed access, protected data and accountable AI.

VibrantAI is designed to help organisations use analytical and AI capabilities while maintaining control over who can access information, how business context is applied, where customer boundaries are enforced and how activity can be reviewed.

Trust is established through role-sensitive access, data protection, customer-specific boundaries, AI controls, privacy practices, traceability and clear shared responsibility. Formal certifications and independent attestations are published when achieved, documented and applicable to the relevant service scope.

Access follows authorised rolesAI remains within governed contextTrust backed by documented controls
VibrantAI Trust Model Enterprise control viewCapability · configuration · assurance
Trust foundation Customer-controlled business context with role-sensitive data, analytical and AI access. Security is applied across the application experience, business objects, data visibility, source access, AI retrieval and administrative functions.
IdentityAuthenticated Access
ApplicationRole Permissions
Business ContextObject Visibility
DataGranular Restrictions
CustomerData Boundaries
AIScoped Retrieval
HistoryAudit and Trace
LifecycleRetention and Deletion
Governing AI principle AI access does not expand the user’s underlying data entitlement—and no raw or readable customer data is shared with the AI provider. EnvisionAI and AskAI retrieve, analyse and present only information authorised for the user and configured business context. Analytical extracts are created and executed within the customer-controlled environment; any limited context used for external AI processing is protected before transmission.
Documented capabilityRole-based and granular visibility
Deployment-specificArchitecture and retention details
Formal assurancePublished only when completed
Govern AccessIdentity, roles, objects and data visibility
Protect InformationProcessing boundaries, encryption and lifecycle controls
Constrain AIAuthorised context, retrieval and provider controls
Demonstrate TrustAuditability, documentation and formal assurance
Trust Principles

Security, privacy and AI governance are applied as one operating discipline.

The trust model covers the complete path from user access and source evidence through analysis, AI interaction, review, collaboration and accountable management action.

Principle 01

Least-necessary access

Users should see only the applications, business objects, data and functions required for their authorised role.

Access is governed at more than one layer.
Principle 02

Customer-controlled context

Business definitions, functional areas, roles, source relationships and AI-enabled experiences are configured for the customer environment.

Customer context is not treated as public or interchangeable.
Principle 03

AI within existing permissions

Natural-language access and synthesis should honour the same underlying data and business-object boundaries as other platform experiences.

AI does not become a permission bypass.
Principle 04

Evidence-backed assurance

Controls, compliance status, independent assessments and certifications are communicated with clear scope and supporting documentation.

Formal assurance is published with its applicable scope and currency.
Identity, Roles and Access

Apply access controls across the experience, business context and underlying data.

Role-based access is most effective when the application, business object and data layers work together rather than relying on a single page-level permission.

01
Application accessControl which platform experiences, functions and administrative capabilities a user can access.
02
Business-object accessControl which Storyboards, functional areas, Plans, Commitments, Value Streams, Conditions or analytical domains are visible.
03
Data-level visibilityApply granular rules for entities such as region, business unit, customer, product, portfolio or other configured dimensions.
04
Administrative separationDistinguish business configuration, data administration, security administration and technical operations where the deployment requires it.
IdentityAuthenticated user and assigned rolesProvisioning and removal follow customer governance.
Business ContextAuthorised objects and domainsFunctional areas, reviews and outcome structures.
Data ContextPermitted entities and detailGranular visibility applied to analytical results.
01Authenticate
02Resolve Role
03Resolve Object
04Apply Data Rule
05Present Authorised View
Customer-specific access design: role-based access, granular visibility and configured data restrictions are applied across the platform. Authentication, provisioning, privileged access and administrative separation are finalized according to the customer’s identity architecture, operating model and security requirements.
Explore the Trust Control Areas

Apply enterprise trust principles through customer-specific control design.

Select a control area to see the protection model, the supporting control evidence and how the capability is configured for each customer environment.

Role and Data Access

Authorise the user before resolving business and data context.

The access model should combine application permissions, business-object visibility and granular data restrictions.

Control objectives

Evidence and documentation

Customer-specific implementation Role-based access and granular visibility are applied across platform experiences, business objects and underlying data. Authentication, provisioning, privileged-role design and administrative separation are configured and documented for the customer’s deployment and identity environment.
Tenant Isolation and Environment Boundaries

Define customer, environment, credential and administrative boundaries explicitly.

VibrantAI applies customer-specific boundaries across application services, data stores, storage, integration credentials, caches, logs and administrative access. The selected isolation model is aligned to the customer’s deployment, security and regulatory requirements.

01
Customer boundaryCustomer-specific information, configuration and credentials are maintained within defined tenant boundaries.
02
Environment boundaryDevelopment, test and production environments should use defined separation, promotion and access practices.
03
Integration boundarySource credentials, connection settings and customer-specific access paths require controlled storage and administration.
04
Administrative boundarySupport and operational access should follow documented roles, approval, logging and customer agreements.
ApplicationCustomer-specific configuration and authorised sessionsBusiness models, roles, pages and analytical context.
DataControlled customer data and evidence pathsDatabases, files, documents, caches and generated outputs.
CredentialsCustomer-specific secrets and integration identitiesAccess to sources is limited to authorised services and approved integration identities.
OperationsDefined administrative and support accessApproval, purpose, duration and activity review.
Customer-specific architecture: the tenant and environment design—including logical or physical separation, storage, logging, credentials and administrative access—is finalized according to the customer’s security, deployment and regulatory requirements. The agreed model is documented through architecture, data-flow, access and operational-control materials.
AI and LLM Controls

Use AI within authorised context, defined provider boundaries and accountable business judgement.

EnvisionAI and AskAI combine natural-language interaction, structured analysis and retrieval-augmented generation. The analytical work is designed to execute within the customer-controlled environment. The trust model constrains what is retrieved, protects any limited context used with an AI provider and governs how the resulting answer is restored, presented and traced.

01
Approved provider strategyEnable AI providers according to customer, deployment, security, contractual and functional requirements.
02
Permission-aware retrievalResolve authorised functional areas, documents, data sources and business objects before retrieving context.
03
Customer-bound analytical executionUse AI to create suitable analytical extracts and logic that execute within the customer system, keeping raw business data inside the trusted customer boundary.
04
Human accountabilityAI can investigate, synthesise and recommend; accountable people retain decision and approval responsibility.
01Authorise User
02Resolve Business Context
03Retrieve Permitted Evidence
04Apply Provider Boundary
05Analyse and Generate
06Present with Trace
No permission expansionAI does not expose data the user is not authorised to access elsewhere in the platform.
No readable customer dataRaw records, readable business keys and actual numeric values are not provided to the AI provider.
No autonomous accountabilityGenerated recommendations do not replace authorised business decisions.
Protected analytical extract model Use AI to shape the analysis while customer data remains protected within the customer-controlled environment. VibrantAI creates suitable analytical extracts and execution logic inside the customer system. When an AI-assisted step requires limited business context, business keys are encrypted or tokenised and numeric values are obfuscated before being supplied to the AI provider. The protected result is returned to the trusted customer boundary, where VibrantAI automatically decrypts the business keys and de-obfuscates the values for presentation to the authorised customer user.
01Analyse inside customer system
02Encrypt keys and obfuscate values
03Use protected AI context
04Return protected result
05Restore inside trusted boundary
Customer-specific AI configuration: the protected-extract model keeps raw and readable customer information inside the customer environment while using encrypted or tokenised identifiers and obfuscated values where limited AI context is required. Approved providers, retention settings, prompt and activity logging, processing location and cross-border requirements are defined in the customer’s AI and security configuration.
Privacy and Data Lifecycle

Govern why information is used, how long it is retained and what happens when the purpose ends.

Privacy is implemented through product configuration, deployment controls, operating procedures and customer instructions. Applicable legal, contractual, geographic and data-category requirements are mapped to the individual customer environment.

01

Define Purpose

Identify the business and analytical purpose for processing.

02

Minimise Data

Use only the data, fields and documents required.

03

Authorise Access

Apply roles, data boundaries and functional context.

04

Process Securely

Use documented source, analytical and AI boundaries.

05

Retain Intentionally

Apply agreed periods to data, results, history and logs.

06

Delete or Return

Support documented offboarding and deletion obligations.

07

Demonstrate

Maintain records needed to explain processing and action.

Auditability and Traceability

Retain the history needed to explain access, configuration, analysis and management action.

Auditability is especially important because VibrantAI connects analytical evidence and AI-assisted interpretation to executive narratives, decisions and actions.

Access

User and administrative activity

Authentication, authorised access, administrative actions and relevant security events according to the implemented logging design.

Who accessed or changed the environment?
Configuration

Business-model and access history

Changes to measures, roles, hierarchies, Storyboards, Commitments, Value Streams and other governed definitions.

Which definition or permission changed?
Evidence

Source, lineage and freshness

The data source, document context, analytical method and evidence age supporting a report, narrative or outcome reading.

What evidence supported the conclusion?
Management

Discussion, decision and action history

Why intervention was required, what was decided, who owned the action and what result followed.

How did evidence become management action?
Customer Control and Shared Responsibility

Platform controls and customer governance must operate together.

Security is not transferred entirely to the provider or entirely to the customer. Responsibilities depend on the deployment, source architecture, contractual scope and enabled platform capabilities.

VibrantAI responsibilities

Operate the documented platform controls

Provide and maintain the agreed SaaS, analytical, integration and AI controls within the defined service boundary.

Implement the documented access and application-control model
Protect platform-managed services, credentials and customer information
Operate logging, monitoring, release and support practices within scope
Document subprocessors, AI providers and material service boundaries as applicable
Support agreed retention, deletion, incident and assurance processes
Customer responsibilities

Govern users, sources, business meaning and authorised use

Configure the platform and connected systems according to the organisation’s access, privacy, risk and records-management requirements.

Approve users, roles, data visibility and administrative access
Maintain source-system permissions, data quality and lawful processing authority
Approve business definitions, AI-enabled use cases and publication rules
Define retention, regional, contractual and sensitive-data requirements
Review exported, shared or externally published content before release
Shared-responsibility principle: the agreed control model is documented in the customer architecture, security schedule, data-processing agreement, AI-provider configuration and operating procedures.
Compliance Status and Assurance Framework

Make assurance status clear, current and evidence-based.

VibrantAI distinguishes platform capability, customer-specific configuration and formal independent assurance so buyers can understand the scope and status of each trust commitment.

Documented capability

Present in current product materials

High-level capabilities such as role-based access, granular visibility, secure dedicated environments, RAG and protected narrative handling.

Must still be validated against the current production release.
Configuration-dependent

Varies by deployment and customer design

Authentication integration, retention periods, AI providers, source access, environment topology, logging scope and administrative separation.

Confirmed through implementation and security documentation.
Formal assurance

Published when achieved and documented

Independent assessments, audit reports, certifications and regulatory positions are communicated with their applicable service scope, date and supporting documentation.

Assurance status remains clear, current and scoped.
Customer-specific trust model: VibrantAI provides a common enterprise trust foundation, while the detailed control architecture, identity integration, tenant design, data lifecycle, AI-provider configuration and compliance mapping are finalized for each customer’s deployment, regulatory and contractual requirements. Formal certifications and independent attestations are published with their applicable scope when achieved.
Enterprise Trust Review

Support due diligence with current, scoped documentation.

The public page introduces the trust model. Enterprise evaluation should use controlled documentation that reflects the actual service and deployment being proposed.

Document 01

Architecture and Data Flow

Service boundaries, customer data paths, integrations, storage, AI providers, environments and administrative access.

Document 02

Control and Responsibility Matrix

Implemented controls, customer configuration, shared responsibilities, exceptions and evidence ownership.

Document 03

Privacy and Data Processing

Processing purpose, data categories, subprocessors, retention, deletion, geographic considerations and customer instructions.

Document 04

AI and LLM Configuration

Enabled providers, retrieval sources, prompt and context boundaries, provider retention settings and human-approval model.

Document 05

Operational Security

Access administration, monitoring, incident handling, change management, backup, recovery and support practices.

Document 06

Formal Assurance Evidence

Current independent assessments, certifications and audit materials with their applicable scope and validity period.

Use enterprise analytics and AI without separating intelligence from governance.

VibrantAI brings role-sensitive access, customer-controlled context, protected evidence, accountable AI and traceable management activity into one enterprise trust model.

Request a Trust Review