Security & Data
Powerful AI. You stay in control.
Private AI keeps model inputs and outputs away from frontier labs. We host and manage private models, connect hosted models, or combine both, with clear permissions and human oversight.
Security & Data
Private AI keeps model inputs and outputs away from frontier labs. We host and manage private models, connect hosted models, or combine both, with clear permissions and human oversight.
Built around your boundaries
The model is only one part of a safe implementation. We agree what it may access and do, test the work, and keep people in control.
Permission
is designed in.
An agreed path from first review to daily operation.
Useful AI should earn your confidence.
Where the model runs is one decision. What it can read, what it can do and when it must wait for a person are equally important. We design the implementation around those boundaries and test the work before launch.
Choose where your information goes
You do not have to send model requests to a frontier AI company. We host and manage private models, connect leading hosted models, or combine both around an agreed data boundary.
Hosted and managed by ProcessRoot
We run open models on ProcessRoot infrastructure or in dedicated cloud environments managed by our team. In a private deployment, model inputs and outputs stay within the private environment rather than being sent to frontier AI providers.
We host, maintain and update the system for you. The hosting location, document storage, logs, backups and support access are agreed as part of the service.
A private assistant searches internal operating procedures and prepares answers for your team.
ProcessRoot-managed private environment
No external AI provider in this model path
We handle the implementation, hosting and ongoing management. Your job is to tell us what the work needs to accomplish and which information must stay protected. The deployment, access and costs are written into the scope.
How ongoing management worksHow control works in practice
These are the operating controls described in our implementation approach. Your agreement defines the workflow, approved actions and responsibilities for your business.
An agent begins in read-only watch mode. The system refuses tools that would write or send until you authorize the work in writing.
Initial outward-facing actions are held for a person to review. A type of action earns more autonomy after twenty clean runs in a row; a correction restarts that review period.
Agree who an agent may contact, what it may say, what it can change and what it must never touch. Unsigned permissions are not granted.
Those limits are enforced by the system around the model. An agent cannot approve a wider scope for itself.
Signing contracts, moving money, deleting client data, taking on subscriptions and pricing outside approved limits remain human responsibilities.
These are restricted actions in the operating system, not simply instructions asking a model to behave. Changes to those boundaries require the owner’s written instruction.
When a request falls outside the workflow’s approved path, it is held for human attention with the context needed to decide what happens next.
The aim is useful, bounded automation: let the system handle the routine path and make the unusual work visible to the right person.
The stop switch returns agents to watch mode and freezes spending. Software cannot release it; a person must authorize the restart.
The system checks itself every five minutes and pulls the stop on its own if it cannot reach its database, its queue or the model your agents run on, if its own heartbeat goes quiet, or if agents start getting refused at the money limits. Work already handed to an email or text carrier cannot be recalled by the switch.
Client records are separated by the database. Credentials for connected systems are encrypted before storage, with decryption keys kept separately from that database.
We do not sell your data. You can request a copy or deletion of the client data we hold. Deletion is handled by a person and recorded. Hosting, support, retention and backup arrangements are agreed for the deployment.
Actions leave a record of what happened, which agent did it, when it happened, and the person who approved or stopped it.
Agents cannot edit that activity record, and you can ask to see it. It gives us a basis for investigating questions, reviewing performance and explaining the work to you.
The same test, whichever model you choose
Our test bench uses the real jobs the system will do, the messages it will prepare and deliberately difficult scenarios designed to expose mistakes. A model that fails the checks is not approved for that workflow.
Newer models go through the same process before replacing an existing one. We choose for the work and the evidence, not simply because a model is new.
Real tasks and representative information.
Unusual requests, misleading inputs and boundary tests.
Review the results before approval and rollout.
Questions worth asking
Yes. We run an open model on ProcessRoot infrastructure or in a dedicated cloud environment managed by our team, so model inputs and outputs do not go to a frontier AI provider in that private model path. We also account for document search, logs, backups, support and integrations when defining the full data boundary.
ProcessRoot hosts and manages the system on our infrastructure or in a dedicated cloud environment. Private describes the model-processing boundary: inputs and outputs stay within that environment instead of going to frontier AI providers. Approved email, text, payment and other integrations still use the services needed to do their jobs.
We assess the exact business service, configuration and agreement. The commercial provider used by our own firm prohibits training on what we send. Training use and storage are different questions, so retention and feature-specific terms are reviewed separately for your implementation.
Model quality depends on the job. We test the chosen model against your workflow before approval. Some work suits a private model; some may benefit from a leading hosted model or a carefully scoped combination. We explain the tradeoffs before you choose.
No. The model does not own its permissions. The operating controls around it enforce the approved scope. Work outside that scope is held for a person.
Yes. That is why testing, limited permissions, human review, records and stop controls matter. They are designed to reduce risk and make problems easier to catch and address. We do not promise that any AI system is risk-free.
This page explains the systems we build for businesses. Our separate Privacy Policy describes this website, its conversation planner, hosting, and your choices.
Start with your business.
More room to serve your customers. To grow your team.
To work on the business you set out to build.