AI Trust.
We take security seriously.
Our AI Platform does too.
We take cybersecurity extremely seriously, and the platform Tech Minded uses implements several steps to ensure the platform is secure and user data is kept private.
AI Trust Center
Security in AI:
Best Practices for Enterprise Implementation
AI security is critical for organizations adopting artificial intelligence solutions. This guide outlines the essential security considerations when implementing AI systems in your organization.
Why AI Security Matters
When implementing AI in your organization, security should be a foundational consideration rather than an afterthought. Without proper security measures, your organization risks:
- Loss of intellectual property
- Exposure of confidential information
- Inconsistent AI outputs across your organization
- Unintended training on your proprietary data
- Without governance, employees take searches and data with them when they leave
Three Key Security Components
-
Data Governance
What it is: Data governance ensures that information entered into AI systems remains within your organization’s control and is properly managed.
Implementation steps:
- Establish clear data ownership policies
- Implement proper user permissions
- Create secure storage protocols
- Define appropriate data retention policies
Why it matters: Just as organizations maintain private business email and file storage systems to retain intellectual property when employees depart, AI systems require similar governance to ensure data remains within the enterprise ecosystem.
-
AI Guardrails
What it is: Guardrails are boundaries that standardize how AI is used within your organization, ensuring consistent outputs and appropriate usage.
Implementation steps:
- Outline approved AI use cases
- Establish style and tone guidelines (yes, the AI has tone)
- Implement content filters for inappropriate outputs
- Create user-specific permissions based on role
Why it matters: Without guardrails, employees may use unsanctioned AI systems that produce inconsistent results or incorporate inappropriate content from personal usage patterns.
-
Protection Against Training on Your Data
What it is: Measures to prevent your proprietary data from being used to train AI models that could later expose your information to competitors.
Implementation steps:
- Select AI providers with clear data usage policies
- Ensure data processing agreements prohibit training
- Implement technical controls to separate “inference” from storage (critical in keeping your data safe)
- Regularly audit data access and usage
Why it matters: Many “free” AI systems monetize by training on user inputs and outputs, potentially exposing sensitive organizational information that could later be reproduced when similar prompts are entered.
How the Platform Secures Data
The platform Tech Minded uses implements a comprehensive security architecture:
- Segregated storage: All conversation histories, user settings, and organizational data reside in secured AWS data centers in Virginia, logically separated by tenant, organization, and user.
- Inference isolation: The architecture deliberately separates the inference layer from historical data storage, ensuring that large language models have no persistent access to previous interactions unless explicitly prompted by the user.
- Multi-cloud approach: Various AI models (including Anthropic, Llama, Mixtral, and Google models) are hosted within controlled environments, while interactions with external APIs like OpenAI are governed by agreements specifying near-zero retention and no training.
- Access controls: Information remains accessible only to authorized individuals and entities based on your organizational settings.
Compliance and Certifications
Security is validated through industry-standard certifications:
- SOC 2 Type I and Type II, and SOC3 compliance
- Regular penetration testing: Independent security firms conduct regular testing of the platform’s systems to identify and remediate potential vulnerabilities.
- External security reviews: Development processes incorporate security reviews at every stage, with external cybersecurity consultants regularly evaluating both code and operational practices.
Core Security Principles of the Platform
- Customer data stays in the platform’s infrastructure. Customer data remains stored within the platform’s infrastructure.
- Minimal inference requests. AI providers receive only minimal inference requests.
- Zero Data Retention agreements. Zero Data Retention (ZDR) agreements are used where available.
- Tenant isolation & strict access controls. Tenant isolation and strict access controls protect customer data.
- No training on customer data. Customer data is never used to train AI models.
Security & Architecture FAQ
-
What security certifications does the platform maintain and how can I get a copy?
The platform maintains SOC 2 Type I, SOC 2 Type II, and SOC 3 attestations. These validate controls around security, availability, confidentiality, and processing integrity.
Copies of SOC 2 & 3 reports can be requested by contacting Tech Minded, or via the platform’s Trust Center portal. A mutual non-disclosure agreement (NDA) will be provided and the report shared.
-
Where is customer data stored?
All customer data is stored primarily in the US and, except for chat history and file storage, is replicated in select geographic regions to optimize performance and availability. Data is segmented across multiple storage systems (user profile, chat history, files, workflow metadata) and is logically separated by tenant, organization, and user.
-
Does the platform train AI models using customer data?
No. There is a strict no-training policy on customer data. Customer data is not used for training by model providers. Zero Data Retention (ZDR) agreements are maintained with key model providers.
-
How does the platform’s architecture protect customer data?
The platform operates as a secure orchestration layer. The architecture deliberately separates the inference layer from historical data storage. When a request is made, the platform constructs the minimal request required for inference and sends only that to the AI provider. AI providers never receive full application datasets or persistent customer storage.
-
What data is sent to AI model providers?
The platform minimizes the information sent to model providers. Full chat histories are not sent in their entirety; context is compacted or summarized, and only relevant document fragments are retrieved for the specific inference needed.
-
What are the data retention policies of AI providers?
The platform uses AWS Bedrock, Google Vertex, Anthropic, OpenAI, and Grok.
- Anthropic & OpenAI: Zero Data Retention agreement in place.
- AWS Bedrock: Prompts and completions are not stored, logged, or used to train models.
- Google Vertex AI: Only retains data for 24h for caching/zero-retention configurations.
- Grok (xAI): API requests are temporarily stored for 30 days for abuse monitoring before being automatically deleted.
-
Can MSPs or customers control which LLM models process their data?
Yes. Administrators can enable or disable specific LLM providers, restricting models based on governance requirements, data residency concerns, or risk tolerance (e.g., preventing users from using a specific model like Grok).
-
Can customer data be deleted and what is the process?
Yes. Core LLM-related application data, user data, and chat history are deleted automatically via a cascading user deletion process. Supporting systems like Stripe (payment), Mailgun (email aggregation metrics), and Salesforce (contract data) may maintain specific records. Deletion of data voluntarily sent to external third-party integrations cannot be guaranteed.
-
What audit capabilities does the platform provide and can you produce access records?
Yes, access records and audit logs can be produced across multiple domains (chats, files, workflows, usage statistics, etc.). A streamlined system for viewing all activity is being expanded. Metadata includes ownership, timestamps, execution status, and model usage.
-
How is tenant isolation enforced?
The platform uses logical tenant isolation combined with strict access controls, including partitioning of chat history by chat ID, separate databases for sensitive content, row-level security policies, runtime authorization validation, and server-side access enforcement.
-
Can platform employees access customer chat history or files?
Access is highly restricted. Support teams do not have routine access to chat history or uploaded files. Engineering access requires controlled procedures, multiple approvals, and active monitoring.
-
What incident monitoring and notification procedures are in place?
Error tracking, intrusion detection, uptime monitoring, infrastructure logging, and health checks are maintained on all services. There is a formal Incident Response Plan (tested annually), continuous vulnerability scanning, annual penetration testing, and an external incident reporting channel.
-
Does the platform support SIEM integration?
Audit and logging capabilities are being expanded. Organizations can currently integrate authentication via SAML/SSO providers to monitor login and access through identity platforms.
-
How does the platform evaluate new AI models before releasing them?
A risk-based approach is followed. Established providers (OpenAI, Anthropic, Google) are introduced quickly. Emerging or open-source models require additional vetting and are typically deployed via trusted hyperscaler environments rather than unknown infrastructure.
-
Does the platform host its own AI models?
Fine-tuned models hosted within the platform’s trusted infrastructure (e.g., AWS) may be introduced in the future. These would follow the same security and data isolation standards.
-
How does the platform handle regulatory privacy requirements?
The platform supports key regulatory data rights, including the right to access and delete data, and offers Data Processing Agreements (DPAs) to align with GDPR and state-level privacy regulations.
-
Is the platform suitable for highly regulated environments?
The platform maintains strong security controls and SOC compliance. Environments requiring specialized frameworks (e.g., FedRAMP, CMMC) should be reviewed on a case-by-case basis.
-
What security improvements are currently on the roadmap?
Priorities include expanded auditing, enhanced log export capabilities, deeper governance controls, and alignment with industry standards such as HIPAA depending on customer demand.
Making it easy for you
No Risk.
No Obligation.
Finding out more is simple, and at no cost. As your advocate, we only want you to secure the services that make sense — whether it's for something new, or replacing an existing solution.
You're in control. Let's talk!
