Home  /  Security & data handling

The answers your risk function will ask for anyway.

Every regulated engagement stalls on the same five questions. Rather than answer them for the first time in a meeting, here they are in writing.

Why this page exists

We advise organisations on approval gates, audit trails and least privilege. A firm that makes that argument and publishes nothing about its own practices is not making a serious argument. Treat this page as the first artifact of the engagement.

Last reviewed 4 September 2026. For anything not covered here, write to contact@axonifi.ai.

The five questions

Where the data goes, and who can see it

01

Where does our data actually run?

In your environment by default. Our standard design deploys into your cloud tenancy — your subscription, your region, your network controls. We do not require data to be copied into an environment we own.

Where a hosted deployment is agreed instead, the region is named in the contract. Where your sector or jurisdiction imposes residency or localisation requirements, we design to keep in-scope data inside that boundary and say so in writing before work begins. Cross-border flows, if any, are enumerated before signature rather than discovered in an audit.

In training, hands-on sessions run on your own licences in your own tenancy. We do not ask you to load real customer data into a classroom exercise, and we will provide masked or synthetic material where a realistic case is needed.

02

Which models, and who chooses them?

Your allowlist, set by your administrator. We work with the assistant and model providers you already hold contracts with — Anthropic, Microsoft, OpenAI, Google, or a model you host yourself. We are not a reseller and take no commission on model spend.

Model choice is bound per job by an administrator, not chosen by an operator in a chat window. Approval and rejection actions never invoke a model at all — a human decision stays a human decision.

Where a workflow can run on a model inside your own perimeter, we will say so, even where that is the harder build.

03

Do you train on our data?

No. We do not train, fine-tune or evaluate any model on your data for any purpose outside your own engagement, and we do not use your data to improve anything sold to anyone else.

Where a retrieval index or fine-tune is part of what you asked us to design, it is built inside your environment, on your data, for your use, and it remains yours.

Your contracts with model providers govern whether those providers may train on inputs. Enterprise tiers generally do not. We will read that clause with you rather than assume it.

04

Who else touches it — subprocessors?

Shorter than most, by design. Our standard architecture puts the deployment inside your own environment. On those engagements no third party we contract touches your operational data at all — the list below covers our own business systems, where your correspondence and the design artifacts live.

The list applicable to your engagement is given to you in writing before signature and forms part of the contract. We add a subprocessor to an active engagement only with notice, and your agreement may require prior consent.

  • Model and assistant providers — chosen by you, not us. We work with whichever provider you already hold a contract with, and the one that applies is named in your engagement’s list. We are not a reseller and take no commission on model spend.
  • Cloud infrastructure — Google Cloud for anything we host ourselves. Where a deployment runs in your own landing zone, it runs on your provider under your account, and we add nothing.
  • Business tooling — Google Workspace, for email, documents and storage.
05

What is retained, and for how long?

Operational records live in your systems, on your retention schedule. Every run, input, output, approver and timestamp is logged — that is the point of the governance layer — and those logs sit in your environment under a period you set. The gate specification records it explicitly for each job.

What we retain is limited to what we need to run the engagement: correspondence, contract records, and the design artifacts we produced. Client operational data is deleted or returned at the end of the engagement on the timetable in the contract.

Deletion is a written step with a confirmation, not an assumption.

Access

How we connect to your systems

The most common security failure in AI projects is not a model leak. It is an over-privileged service account created in week one and never reviewed.

Credentials

Nothing holds your passwords

Systems are connected through scoped service accounts, OAuth or delegated identity issued by you. We do not ask for, store or share individual user passwords, and will not accept them if offered.

Privilege

Read and write separated

Every connector is provisioned with the narrowest scope the job requires, with read and write held as separate grants so a drafting capability cannot quietly become an executing one.

Review

Access expires

Engagement access is time-bound and reviewed at each phase boundary. At the end of an engagement, revocation is a named task with a sign-off, not a loose end.

The gate

Approval is a security control

The write boundary is not only governance. It is the control that means a compromised prompt, a bad retrieval or a model error cannot execute anything alone — every consequential action still needs a named human.

Practice

People, devices and incidents

  • Named individuals only. Everyone working on your engagement is named to you. Partner personnel are named and bound by equivalent obligations.
  • Confidentiality. NDAs as standard; background verification on request for regulated engagements.
  • Devices. Full-disk encryption, screen lock, managed updates, MFA on every account that touches client material.
  • Secrets. Credentials in a managed secret store — never in source, chat, tickets or documents.
  • Least data. Masked or synthetic data during design and training wherever a real record is not strictly required.
  • Classroom material. Anything produced in a training session belongs to you and is returned or deleted at the end.
Incident responseOur contractual commitment
on becoming aware of an incident affecting your data

  notify named client contact ....... within 24 hours
  written preliminary assessment .... within 72 hours
  containment actions ............... reported as they occur
  root cause and remediation ........ written, on close

your escalation path
  security contact ... contact@axonifi.ai
  named responder .... Rajeev Belani
  out of hours ....... phone, in contract

what we will not do
  delay notification pending investigation
  report through an account manager instead
    of your security contact
Next step

Bring your risk team to the first call

Most firms want the business sponsor alone in the room early. We would rather have the person who will eventually block it. Ninety minutes, one workflow, an honest answer.