Max OS

Trust

Your people are already pasting company information into AI products.

Not because they are careless. Because those products are useful and nobody told them not to.

This is the alternative.

Your knowledge is not on the internet

Your brain stays in the country, and it never trains anything.

Your company brain is held in the United Kingdom, on UK infrastructure, under a UK company, in an environment used by your business and nobody else. No other client, and no other client's agent, can reach it.

When a question needs a model to interpret it, only the minimum text required to answer goes out. Never the brain, never your credentials, never access to your systems.

Nothing in your brain is used to train anything, by us or by anyone else.

Which means the safest place for your people to ask a question is the one you control.

Two clients. Two brains. Nothing crosses.

Not everyone sees everything

A question returns what that person is allowed to see.

Access is set by you, by role. Who can see what, who can approve, who can only prepare.

The same question asked by someone in operations and by a director returns different answers, because they are allowed to know different things. The brain does not answer around a permission because it was asked politely, and it does not mention that something exists but cannot be shown.

Every access change is logged. Access can be removed instantly.

Nothing acts without you

The system prepares. A person approves. Nothing goes out on its own.

Reading approved information happens on its own. Anything that changes a record needs confirmation. Anything that reaches a customer needs a person. Anything that cannot be undone needs more than that.

Where the evidence is not there, your agent says so rather than filling the gap. It routes the question to someone who knows.

Everything is recorded: what was asked, what was retrieved, what was done, who approved it, and what came back.

What we keep, and what happens when you leave

Approval decisions and access changes are logged for the length of the engagement and for twelve months after, unless you ask for earlier deletion.

The company brain, the workflows and your agent's configuration are yours. On termination you get a full export within thirty days, everything on our infrastructure is deleted, and you get written confirmation that it has been.

Where we are heading

Architecture and practice, not aspiration. Nothing below is claimed until it is held.

ICO registered Working through Cyber Essentials Then IASME Cyber Assurance Then ISO 42001

The full data protection and guardrails statement is available as a PDF on request, or read it on this site.

Ask us anything you would ask a supplier holding your data.

See where to start