Governance

AI you can put in front of clients.

Nothing reaches a client without a human sign-off — and everything else is scoped, encrypted, and audited on the way there.

Illustration of an audit trail: a draft is generated, sent for review, and approved by its accountable owner — while, once a second person is active, the runner’s attempt to approve their own work is rejected by the server.

The review gate

Maker and checker, enforced in code.

The rule every agency already runs on paper, made structural: the person who generated the work can never be the one who approves it.

Maker

Runs the brief, generates options, requests review.

Review gate

ApproveRequest changes

Checker

The accountable owner approves, rejects, or sends back with notes.

Maker-and-checker separation is a server invariant, not a setting — the moment a second person is active, self-approval is blocked.

Governance

Control is part of the product.

The safeguards are not policy text around an AI tool. They are enforced in the workflow, permissions, credentials, and audit record.

  • Review gate enforced in code

    No output is client-ready without a recorded sign-off — and, once a second person is active, never self-approved.

  • Capability-level access

    Roles are built from capabilities, not job titles — and permissions fail closed: anything not explicitly granted is denied.

  • Two-factor authentication

    TOTP 2FA, enforceable per agency security policy.

  • Encrypted and audited

    Provider credentials are encrypted at rest with a key only the operator holds — a backup without it is unreadable — and sensitive actions land in the audit log.

Data control

Your data, where you decide.

Client work lives in storage you choose; the credentials that reach it are encrypted with a key only the operator holds — hosted, self-hosted, or fully offline.

  • Storage you point at

    Working files live in your storage — local disk, S3, Google Cloud Storage, Google Drive shared drives, SFTP, or FTPS — under a readable client/brand/campaign layout your own tools can reach. The database keeps references, never the bytes.

  • Residency, per client

    A client that must keep its work in its own bucket — or on its own AI provider account — gets exactly that. Storage credentials and provider keys override per client, with no separate deployment.

  • Retention on your terms

    Audit and feedback records follow windows you set: personal details are redacted first, records purged later. Nothing is silently deleted — or silently kept — and changing a window is itself audited.

  • Hosted, self-hosted, or air-gapped

    Run on our cloud or entirely on your own infrastructure at the same price — with an offline option for the strictest environments. Client data stays in the operator’s hands either way.

Quick answers

All questions
01
Where does our client data live?
In storage you choose — from the local disk on your own server to your own bucket, drive, or SFTP. The database stores references to files, never the files themselves, and hosted and self-hosted installations run the same code at the same price.
02
Is our client data used to train shared AI models?
No. Each client’s agent draws on that client’s own context and review history at generation time. Nothing is fine-tuned into a shared model, and one client’s material is never visible to another client’s agent.
03
Can one client require its own storage or AI account?
Yes. Storage credentials and AI provider keys can be set per client, so a client with residency or procurement requirements runs on its own bucket and its own keys — inside the same installation.
04
What happens to work that isn’t approved?
It stays on the record. Rejections — and their reasons — steer future generations away from what that client declines; unselected options wait, ready to grade whenever the team returns to them.
05
What do the AI providers see?
Only the scoped context for that task — the brief and the client material relevant to it, never another client’s. Bring your own keys and the call runs on your provider account, so your own DPA and retention terms govern that leg — and a client with stricter requirements routes to its own account entirely.

Data control

Your data, where you decide.

  1. 01

    Storage you point at

  2. 02

    Residency, per client

  3. 03

    Hosted, self-hosted, or air-gapped

  4. No output is client-ready without a recorded sign-off — and, once a second person is active, never self-approved.

The questions your ops and legal people will ask.

Prove it on one client

Put AI in front of clients — with the controls to prove it.

Evaluate the full workflow in mock mode, then deploy under your agency's brand.

No AI keys. No card. Nothing reaches a client without review.