Security
Your ledger is the most sensitive data you will ever share.
Recovery Agent is designed for UK GDPR, multi-tenant segregation and evidence handling that stands up to internal audit.
Platform controls
How access is constrained
- Segregated organisation and workspace per customer
- Row-level security on every customer-data table
- Private storage buckets with segregated paths
- Expiring signed URLs for document access
- Multi-factor authentication for privileged users
- Inactive-session timeouts
- Encryption in transit and at rest
- Append-only audit logging
- Sensitive file access and download logging
- Explicit engagement assignment for internal staff
- Counterparties see only formally shared records
- Configurable retention, export and deletion workflows
Responsible agents
Governed AI, not autonomous action
- Server-side model calls only; no credentials in client code.
- Structured outputs validated before they are stored.
- Outputs without valid source citations fail.
- Every agent run records its inputs, prompt version, model and reviewer.
- Agents cannot send correspondence, approve settlements, confirm recovery or invoice.
- Agent outputs are labelled 'Agent-assisted draft' until a human approves them.
What we do not do
- We do not use customer data to train public models.
- We do not use one customer's data for another customer.
- We do not create cross-customer benchmarks without explicit rights and effective anonymisation.
- We do not place confidential information in browser logs.
- We do not claim ISO 27001, SOC 2, Cyber Essentials or any other certification. Where certification is achieved it will be stated explicitly with its scope and date.
Due diligence welcome.
We will walk your security, data protection and internal audit teams through the platform controls before any data is shared.