Trust & security
Last updated: September 1, 2026
An AI employee works inside the systems that run your company. That only makes sense if every action it takes is scoped, supervised, and recorded. This page describes how we do that — what an AI employee is allowed to touch, who approves the things that matter, and what evidence you are left with afterward.
Encrypted end to end
TLS 1.2+ in transit, AES-256 at rest, on managed infrastructure with tenant isolation.
Scoped permissions
Every AI employee gets per-system, per-action access. Anything outside that scope is denied and logged.
No model training
Your data is never used to train foundation models, ours or a provider's.
Mexico and U.S. residency
Operational data is stored in the region you choose at the start of the engagement.
1. How an AI employee is scoped
Before an AI employee goes live, we define exactly what it can reach. Scope is written down during implementation, approved by you, and enforced technically — not by prompt instructions:
- Which systems it connects to (ERP, CRM, email, file storage, messaging) and with which credentials.
- Whether access to each system is read-only or includes write actions.
- Which specific actions it may take, and which require human approval first.
- Monetary, volume, or sensitivity thresholds above which it must stop and escalate.
- Which data categories are out of scope entirely — payroll, medical records, or anything else you exclude.
Scope changes go through the same review as the initial deployment. Nothing expands silently.
2. Human approval and escalation
AI employees propose; people decide on anything consequential. Actions that create financial exposure, change a record of record, or communicate externally on your behalf can be configured to require a named approver. When an AI employee is uncertain, or when a case falls outside the patterns it was trained on, it escalates to the human owner of that process instead of guessing.
3. The audit log
Every AI employee writes to an append-only log. Each entry records what was proposed, who approved or rejected it, which system it hit, and when — including attempts that were blocked by permissions. The log is available to you throughout the engagement and can be exported for internal or external audit.
- Timestamped, attributable entries for every proposed and executed action.
- Blocked and denied attempts recorded alongside successful ones.
- Human approvals recorded with the approver's identity.
- Export in a machine-readable format for your own retention or audit.
4. Infrastructure and encryption
IntegrAI runs on established cloud infrastructure rather than hardware we operate ourselves.
- Data in transit is encrypted with TLS 1.2 or higher.
- Data at rest is encrypted with AES-256.
- Each customer's data is logically isolated; there is no shared operational store across customers.
- Keys and integration credentials are held in a managed secrets service, never in application code or configuration files.
- Production environments are separate from development and testing environments, which do not use live customer data.
5. Access control inside IntegrAI
Access to customer environments is limited to the people who need it to deliver the engagement.
- Single sign-on with multi-factor authentication for all internal systems.
- Least-privilege access, granted per engagement rather than per employee.
- Access is reviewed periodically and revoked on role change or departure.
- Administrative access to customer systems is logged.
- All personnel are bound by confidentiality obligations.
6. Models and your data
AI employees are built on commercially available foundation models accessed through enterprise agreements.
- Your data is not used to train foundation models — ours or any provider's.
- We use enterprise API tiers with no-training terms and, where the provider offers it, limited or zero retention.
- Data from one customer is never used to improve the AI employees of another.
- Where a process can be handled without sending data to a model at all, we design it that way.
7. Integrations with your systems
Connections to your systems use credentials you issue and can revoke.
- We ask for the narrowest scope that lets the process work — a service account with specific permissions, not an administrator login.
- Credentials are stored in a managed secrets service and rotated on a defined schedule.
- You can revoke any credential at any time; the affected AI employee stops and reports rather than failing silently.
- Where your system supports its own audit trail, actions remain attributable to the AI employee's service account.
8. Monitoring, testing and incident response
- Dependencies and infrastructure are scanned for known vulnerabilities on an ongoing basis.
- Changes are reviewed before reaching production.
- We maintain a documented incident response process with named owners.
- In the event of a security incident affecting your data, we will notify you without undue delay and in any case within 72 hours of confirming it, with what we know and what we are doing about it.
9. Continuity and recovery
Configuration, audit logs, and operational data are backed up on a regular schedule, with restores tested periodically. If an AI employee has to be taken offline, the processes it runs revert to the manual path your team used before — we document that fallback as part of implementation, so an outage is an inconvenience rather than a stoppage.
10. Compliance posture
We process personal data in accordance with Mexico's Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP) and, where a customer's operations require it, with the data protection commitments set out in that customer's agreement. Our internal controls are built against the practices that underpin recognized security frameworks, including SOC 2 and ISO/IEC 27001. We do not claim certification we have not completed; current certification and audit status is available on request and will be published here as it changes.
11. Reporting a vulnerability
If you believe you have found a security issue in our website or platform, write to security@integrai.com.mx with enough detail to reproduce it. We acknowledge reports within two business days, keep you informed while we investigate, and will not pursue action against good-faith research that avoids privacy violations, service disruption, and data destruction.
12. Security contact
For security questionnaires, due diligence requests, architecture reviews, or anything else on this page:
- Email: security@integrai.com.mx
- Website: integrai.com.mx
This page describes the security practices IntegrAI applies to its engagements. It is a description of our practices, not a contract; the specific commitments for a given engagement are the ones written into that customer's agreement.