Built to be audited.
Data isolation enforced in the database, not in application code. Every action through the same gate. Every decision recorded with its reasoning chain.
This page is not gated behind a form. Your security team can read it before they talk to us.
Tenant isolation in the database
Row-level security enforced in Postgres across 89 tenant-scoped tables — not in application code. The application role cannot bypass RLS. An unknown tenant receives zero rows, silently. Your security team can be given a login and invited to try to reach another tenant's data.
Enforcement: RLS policies in every migration. Verified by cross-tenant negative tests.
Governed autonomy
Every action routes through the same pipeline: preview, confirm, execute, audit. Human approval above configurable thresholds. The AI never moves money without a human (ADR-028), never reaches data it should not, and never acts without a record.
Enforcement: Action Framework classify(): read-only executes, non-financial writes confirm, agent-financial or amounts over $500K require human approval. Property-test enforced.
Append-only audit trail
Every agent decision recorded with the full reasoning chain. The application role has SELECT and INSERT only on the audit table — no UPDATE, no DELETE. The codebase raises on any attempt to delete an audit record. Designed for 7-year retention.
Enforcement: Migration 007 grants SELECT+INSERT only. Repository layer raises on audit delete.
Data classification
Every table in the system carries an explicit sensitivity classification across four tiers: Permanent, Legal Retention, Operational, and Ephemeral. Three-layer overrides — platform, vertical, tenant — with the most restrictive tier winning.
Enforcement: 21 tests. 57 tables classified. PII fields flagged.
Three-audience data isolation
Party-scoped access: an internal team, a client, and a customer each see only their data. A customer cannot see another customer's records, fees, or engagement internals. Boundary enforced in Postgres by row-level security and access layers, not by application-level filtering.
Enforcement: Access module with Party × Role RBAC. Layer enforcement via migration 020. Verified live across audiences.
Compliance posture
Designed for businesses handling client-confidential data under professional obligations. POPIA and GDPR considerations built into the data model. Supervised communications produce an append-only audit record before content is returned. Monitoring is disclosed, not hidden.
Enforcement: Communications audit writes before returning content. Retention tiers from the data classification system.
The AI questions your security team will ask
These are the questions that kill AI deals. Here are the answers, with specifics.
Which AI model, and does our data train it?
Anthropic Claude, through Anthropic's commercial API. Exarity does not use your data to train models, and Anthropic's commercial terms do not permit training on API data. Voice features are optional: when used, speech-to-text runs in your browser's speech service or through Groq, and text-to-speech through Microsoft's speech service.
What can the AI do without a human?
Read-only operations execute immediately. Non-financial writes require confirmation. Any financial action — or any action by an autonomous agent — requires human approval. Actions over $500K require an additional approval gate. This is encoded in the Action Framework, not in policy documents.
How are AI decisions audited?
Every decision carries a full reasoning chain, written to an append-only audit table: the application database role has INSERT and SELECT only — no UPDATE, no DELETE. Designed for 7-year retention. Exportable for regulatory review. (See the note on durable audit storage below.)
Can an action be reversed?
Every action passes through preview → confirm → execute. The preview shows what will happen. The confirmation token is single-use with a 5-minute TTL. The audit trail records what was done, enabling informed reversal.
How is prompt injection handled?
Three layers: (1) Instruction hierarchy — system instructions take precedence over user input, which takes precedence over external data. External content is tagged as untrusted. (2) Architectural separation — the assistant treats tool results as data, never as instructions. The capability registry is the sole source of available actions. (3) Financial safety net — even a successful injection cannot bypass the approval gates for writes and financial actions.
Where is our data stored?
Default deployment: AWS af-south-1 (Cape Town, South Africa). Customer data at rest stays within that region. Requests to the AI model are processed by Anthropic outside South Africa; how long Anthropic keeps API data is governed by its commercial terms, which we provide on request. See our Data Processing Agreement for details.
What we do not claim
- We are not SOC 2 certified and have not yet engaged an auditor. The platform is being built toward SOC 2 Type II control objectives.
- An independent penetration test has not yet been performed.
- Field-level encryption of personal information is built but not yet switched on. Data is encrypted at rest by the database storage layer and in transit with TLS.
- A defect that stopped the AI decision audit trail from being stored durably was fixed on 28 September 2026 and is being rolled out.
- External communications transports (email, WhatsApp) are architecturally complete but not yet connected to live providers.
Have a security questionnaire?
Send it to security@exarity.com — we answer from an evidence-backed bank and typically respond within 5 business days.