Security & Privacy

How We Handle Access, Approvals and Data

Automation touches real systems and real customers. These are the commitments that govern how we work with yours.

AccessApprovalLogYour dataRollbackYour keys

Our Commitments

Data

Your Data Stays on Your Infrastructure

Your AI runs on infrastructure you own: your own cloud account or VPS. Your business data and workflows run on your infrastructure, not on Gengrid Solutions servers. Your records never have to leave your control.

Access

Least-privilege Accounts You Control

You create least-privilege accounts for us, and you can revoke our access at any time. Each account has only the permissions needed for its job and nothing more. Removing it takes effect immediately, without asking anyone.

Transparency

A Monthly Access Log

A log of our access to your systems is shared with you every month. It shows which systems were accessed and when. Anything unexpected can be raised and explained straight away, while the details are still fresh.

Approvals

People Approve Irreversible Actions

Irreversible actions need a human approval; if no approval arrives, nothing happens. Payments, deletions and commitments to customers wait for a named person to confirm. A missed approval therefore means a delay, never a mistake that cannot be undone.

Customers

People Approve What Customers See

Our agents do the work; a human approves anything that reaches a customer or a prospect. Replies, messages and documents are drafted automatically but checked by a person before they are sent. The business stays responsible for every word a customer reads.

Callers

Honest with Callers

Callers are told they are speaking with an AI. Emergency calls are never handled by the AI; they go straight to a person or the public network. Being open about this builds trust and avoids confusion.

Changes

Careful Deployment

Before any deployment we run a pre-flight audit of your hardware or cloud account. We roll out in stages, and every change has a rollback plan. Problems are caught early, while they are still small.

Exit

No Lock-in

If you leave, the system stays on your infrastructure and we hand over access and documentation, including a credential transfer plan. The handover is planned from the start, not left until the end.

Prepared actionSend to customerMove moneyDelete a recordHOLDApproval gateApproved,then carried out

What to Check With Any AI Supplier

Whoever you work with, these points help you understand the risks. Clear written answers on each one are a good sign that a supplier takes security seriously. Vague answers are a warning sign.

Monthly access logSharedwith youeach month

Where It Runs

Find out on whose servers or accounts the system runs, and who pays for them. A system on your own account keeps your data and your bill under your control. A system on a supplier's servers means your records pass through theirs.

Who Can Access What

Establish which accounts the supplier uses and whether you can switch them off yourself. Good practice is a separate, limited account for each person or system. Any access should be visible to you and removable at any time.

What It Can Do Without a Person

Agree which actions need a human approval, and what happens if nobody approves. Anything that cannot be undone, such as a payment or a message to a customer, should wait for a person. Silence should mean nothing happens.

What Happens If You Leave

Settle what you receive when the relationship ends and whether the system keeps working. Documentation, access and credentials should be handed over in a planned way. Leaving should not mean starting again from nothing.

Guide

What to Check with Any AI or Automation Supplier

Access

Anyone who builds or supports automation needs some access to your systems. The question is how much, for how long, and whether you can see and withdraw it. Good practice is a separate account per person or system, with only the permissions needed for the job, created by you and removable by you.

Which accounts will be needed, and with what permissionsA full list of every access held, which you can remove yourselfWhether shared or administrator logins are ever usedHow passwords and keys are stored on the supplier's side

Approvals

Automation should not take irreversible actions on its own. Ask which actions need a person's approval, who that person is, what happens if nobody approves, and whether approvals are recorded. A good answer is specific: sending to customers, moving money and deleting records all wait for a named person.

Logging

You should be able to find out what was done, when and by whom, both by people and by the system. Ask what is logged, where the logs are kept, how long for, and whether you receive them. Logs are what turn a mystery into a quick fix when something goes wrong.

Data Handling

Where data is stored, and in which countryWhich outside services see it, including AI providersWhether any of it is used to train modelsHow long it is kept, and how it is deletedWhat leaves your infrastructure, and exactly what it contains

When Things Go Wrong

Ask how incidents are detected, how quickly you will be told, and who does what. Ask for the rollback plan for changes and the recovery steps if a server fails. A supplier who has thought about failure is more trustworthy than one who promises it will not happen.

Leaving

Ask what happens on the last day: which accounts are closed, what documentation you keep, whether the system keeps running, and how access is handed back. The answer tells you how dependent you will become.

Your Side of Security

Turn on two-step login for every administrator account you ownReview who has access every quarter, and remove anyone who has leftKeep a named owner for each automated systemTrain staff to check before approving anything unusual

Phishing and Approval Fraud

As more work is approved through messages and buttons, attackers target the approver. Train the people who approve actions to be suspicious of urgency, new bank details and requests that arrive outside the usual channel, and to confirm by phone when in doubt.

Talk to Us About Security

Send your security concerns and they will be answered in plain language. Specific details, such as the systems and information involved, make the answers more useful. Nothing technical is assumed.

Discuss Your Requirements