Customer-controlled sources
Connect only the sources the organization approves.
Security
OfRoot designs company AI and automation systems around approved sources, explicit permissions, visible system behavior, and human control for sensitive actions.
Architected to support organization-specific privacy and security requirements. Specific controls depend on the selected architecture and customer environment.
Connect only the sources the organization approves.
Apply user and source permissions before returning context.
Link important answers to the material used to produce them.
Design tenant and customer boundaries as explicit system contracts.
Use encryption in transit and at rest where supported by the selected infrastructure.
Limit access by job responsibility and approved workspace.
Record meaningful access and system actions for review.
Keep sensitive actions behind an explicit person or authorized workflow.
Choose providers and deployment patterns based on the use case and risk.
Evaluate dedicated or private infrastructure when requirements justify it.
Honest boundary
We do not claim HIPAA, SOC 2, GDPR, or another certification by default. During discovery, we identify the actual requirement, the systems in scope, the responsible parties, and the evidence needed to validate the final design.
Explore Private Company AI →