Security and data protection

AI in your business software, within limits you set.

An application that touches your sales and production data has to pass your IT department. We build for that from the first day.

Your environment
  1. It works as the user.
  2. A person approves.
  3. We log the action.
Data handling

Your data stays where it is

We build the application where your data already lives, so your data travels to as few places as possible.

  • Location

    In your Salesforce org or on your own infrastructure. We keep no copy of your data.

  • Data sent to a model

    You and your IT decide which data a model receives, per application, before we start building.

  • Model training

    The models we use do not train on your data. We name the model provider and the platform in each project.

  • Processing region

    EU data residency is available. You and your IT choose the region and hosting.

Agent controls

An agent works within the user's permissions

An agent that acts needs limits and a record of what it did.

  1. 01

    It works as the user.

    It inherits the permissions of the person who started it. It sees only what that person may see.

  2. 02

    A person approves.

    A person says yes before an agent changes data or sends a message.

  3. 03

    We log the action.

    The log records what the agent did and for whom.

Secure development

You can review what we build

You receive the source code and the documentation, so your IT team or an outside reviewer can inspect them.

  • Code review

    Another developer reviews each change before it ships.

  • Automated tests

    Tests flag a change that breaks something, including a change made with AI.

  • Managed secrets

    Keys and credentials stay out of the code and live in a managed secrets store.

  • Dependency checks

    We check third-party packages for known vulnerabilities.

  • Documented architecture

    We document structure, data model and decisions, so a reviewer can follow what the AI built.

  • Salesforce platform and AppExchange

    Our three products on the Salesforce AppExchange have passed its security review. Applications we build inside your org follow Salesforce's platform security model.

Data protection

What your data protection officer will ask for

We have these ready before the first project day.

  • Data processing agreement (AVV)

    We sign it before the project starts.

  • Sub-processor list

    We send it on request, with each provider and its role.

  • A direct contact

    Your security or data protection team can write to contact@ibs-technology.com.

An example you can try

This site reads public pages only

The tailored homepage reads your public website and a few searches. It keeps the facts it can quote and shows the pages and sources it used. Where it cannot know something from outside, it says so.

Tailor the homepage to your company
Security

Questions your IT team will ask

Which AI do you use, and where does our data live?

The application runs in your Salesforce org or on your infrastructure. We choose the model and the platform with your IT, against your data-protection and data-residency requirements. The models do not train on your data, and EU hosting is available.

What can an AI agent do in our systems?

Only what the user who runs it may do. It inherits that user's permissions. A person approves any action that changes data or sends a message, and we log each action.

Do you sign a data processing agreement?

Yes. We sign a data processing agreement (AVV) before the project starts, and we send our sub-processor list on request.

Can we review how the application is built?

Yes. You receive the source code and the architecture documentation, so your IT team or an outside reviewer can inspect them.

Send this page to your security team.

They can write to us before the call at contact@ibs-technology.com.