AI in your business software, within limits you set.
An application that touches your sales and production data has to pass your IT department. We build for that from the first day.
- It works as the user.
- A person approves.
- We log the action.
Your data stays where it is
We build the application where your data already lives, so your data travels to as few places as possible.
Location
In your Salesforce org or on your own infrastructure. We keep no copy of your data.
Data sent to a model
You and your IT decide which data a model receives, per application, before we start building.
Model training
The models we use do not train on your data. We name the model provider and the platform in each project.
Processing region
EU data residency is available. You and your IT choose the region and hosting.
An agent works within the user's permissions
An agent that acts needs limits and a record of what it did.
- 01
It works as the user.
It inherits the permissions of the person who started it. It sees only what that person may see.
- 02
A person approves.
A person says yes before an agent changes data or sends a message.
- 03
We log the action.
The log records what the agent did and for whom.
You can review what we build
You receive the source code and the documentation, so your IT team or an outside reviewer can inspect them.
Code review
Another developer reviews each change before it ships.
Automated tests
Tests flag a change that breaks something, including a change made with AI.
Managed secrets
Keys and credentials stay out of the code and live in a managed secrets store.
Dependency checks
We check third-party packages for known vulnerabilities.
Documented architecture
We document structure, data model and decisions, so a reviewer can follow what the AI built.
Salesforce platform and AppExchange
Our three products on the Salesforce AppExchange have passed its security review. Applications we build inside your org follow Salesforce's platform security model.
What your data protection officer will ask for
We have these ready before the first project day.
Data processing agreement (AVV)
We sign it before the project starts.
Sub-processor list
We send it on request, with each provider and its role.
A direct contact
Your security or data protection team can write to contact@ibs-technology.com.
This site reads public pages only
The tailored homepage reads your public website and a few searches. It keeps the facts it can quote and shows the pages and sources it used. Where it cannot know something from outside, it says so.
Tailor the homepage to your companyQuestions your IT team will ask
Which AI do you use, and where does our data live?
The application runs in your Salesforce org or on your infrastructure. We choose the model and the platform with your IT, against your data-protection and data-residency requirements. The models do not train on your data, and EU hosting is available.
What can an AI agent do in our systems?
Only what the user who runs it may do. It inherits that user's permissions. A person approves any action that changes data or sends a message, and we log each action.
Do you sign a data processing agreement?
Yes. We sign a data processing agreement (AVV) before the project starts, and we send our sub-processor list on request.
Can we review how the application is built?
Yes. You receive the source code and the architecture documentation, so your IT team or an outside reviewer can inspect them.
Send this page to your security team.
They can write to us before the call at contact@ibs-technology.com.