Skip to main content
OfRoot

Security

Control the knowledge. Control the access. Keep the evidence.

OfRoot designs company AI and automation systems around approved sources, explicit permissions, visible system behavior, and human control for sensitive actions.

Architected to support organization-specific privacy and security requirements. Specific controls depend on the selected architecture and customer environment.

Customer-controlled sources

Connect only the sources the organization approves.

Permission-aware retrieval

Apply user and source permissions before returning context.

Source-backed responses

Link important answers to the material used to produce them.

Data isolation

Design tenant and customer boundaries as explicit system contracts.

Encryption

Use encryption in transit and at rest where supported by the selected infrastructure.

Role-based access

Limit access by job responsibility and approved workspace.

Audit logging

Record meaningful access and system actions for review.

Human approval

Keep sensitive actions behind an explicit person or authorized workflow.

Model-provider flexibility

Choose providers and deployment patterns based on the use case and risk.

Private deployment options

Evaluate dedicated or private infrastructure when requirements justify it.

Honest boundary

Architecture is not certification.

We do not claim HIPAA, SOC 2, GDPR, or another certification by default. During discovery, we identify the actual requirement, the systems in scope, the responsible parties, and the evidence needed to validate the final design.

Explore Private Company AI →

Start with your sources, access rules, and risk boundaries.

Book a Growth Systems Audit