Governance
AI you can put in front of clients.
Nothing reaches a client without a human sign-off — and everything else is scoped, encrypted, and audited on the way there.
Illustration of an audit trail: a draft is generated, sent for review, and approved by its accountable owner — while, once a second person is active, the runner’s attempt to approve their own work is rejected by the server.
The review gate
Maker and checker, enforced in code.
The rule every agency already runs on paper, made structural: the person who generated the work can never be the one who approves it.
Maker
Runs the brief, generates options, requests review.
Review gate
Checker
The accountable owner approves, rejects, or sends back with notes.
Maker-and-checker separation is a server invariant, not a setting — the moment a second person is active, self-approval is blocked.
Governance
Control is part of the product.
The safeguards are not policy text around an AI tool. They are enforced in the workflow, permissions, credentials, and audit record.
Review gate enforced in code
No output is client-ready without a recorded sign-off — and, once a second person is active, never self-approved.
Capability-level access
Roles are built from capabilities, not job titles — and permissions fail closed: anything not explicitly granted is denied.
Two-factor authentication
TOTP 2FA, enforceable per agency security policy.
Encrypted and audited
Provider credentials are encrypted at rest with a key only the operator holds — a backup without it is unreadable — and sensitive actions land in the audit log.
Data control
Your data, where you decide.
Client work lives in storage you choose; the credentials that reach it are encrypted with a key only the operator holds — hosted, self-hosted, or fully offline.
Storage you point at
Working files live in your storage — local disk, S3, Google Cloud Storage, Google Drive shared drives, SFTP, or FTPS — under a readable client/brand/campaign layout your own tools can reach. The database keeps references, never the bytes.
Residency, per client
A client that must keep its work in its own bucket — or on its own AI provider account — gets exactly that. Storage credentials and provider keys override per client, with no separate deployment.
Retention on your terms
Audit and feedback records follow windows you set: personal details are redacted first, records purged later. Nothing is silently deleted — or silently kept — and changing a window is itself audited.
Hosted, self-hosted, or air-gapped
Run on our cloud or entirely on your own infrastructure at the same price — with an offline option for the strictest environments. Client data stays in the operator’s hands either way.
Quick answers
All questions- Where does our client data live?
- In storage you choose — from the local disk on your own server to your own bucket, drive, or SFTP. The database stores references to files, never the files themselves, and hosted and self-hosted installations run the same code at the same price.
- Is our client data used to train shared AI models?
- No. Each client’s agent draws on that client’s own context and review history at generation time. Nothing is fine-tuned into a shared model, and one client’s material is never visible to another client’s agent.
- Can one client require its own storage or AI account?
- Yes. Storage credentials and AI provider keys can be set per client, so a client with residency or procurement requirements runs on its own bucket and its own keys — inside the same installation.
- What happens to work that isn’t approved?
- It stays on the record. Rejections — and their reasons — steer future generations away from what that client declines; unselected options wait, ready to grade whenever the team returns to them.
- What do the AI providers see?
- Only the scoped context for that task — the brief and the client material relevant to it, never another client’s. Bring your own keys and the call runs on your provider account, so your own DPA and retention terms govern that leg — and a client with stricter requirements routes to its own account entirely.
Data control
Your data, where you decide.
01
Storage you point at
02
Residency, per client
03
Hosted, self-hosted, or air-gapped
No output is client-ready without a recorded sign-off — and, once a second person is active, never self-approved.
Prove it on one client
Put AI in front of clients — with the controls to prove it.
Evaluate the full workflow in mock mode, then deploy under your agency's brand.
No AI keys. No card. Nothing reaches a client without review.