SECURITY & GOVERNANCE

Control who sees, changes and sends.

PrivDesk treats identity, tenant isolation and human approval as part of the support workflow. The current evidence is from local Core and browser tests.

Review your requirements
REVIEW BOUNDARY
  1. Authenticated staff access
  2. Organization scoped context
  3. Policy checked draft
  4. Human approved reply
No customer message is sent by AI alone.
LOCAL CONTROL EVIDENCE

Controls built into the journey.

These behaviors have local implementation and selected tests. Production certification, penetration testing and hosted acceptance are later gates.

Access tied to role and organization

Core separates platform operators, company owners and agents, and customer portal users. Local QA covers cross-tenant denial, session revocation and logout.

Customer content stays scoped

Requests, cases and knowledge have organization access rules. Staff-only notes are excluded from customer portal responses.

Review before customer impact

Knowledge publication and AI drafts have human review steps. Approved AI text remains unsent until a staff member sends the reply.

AI GOVERNANCE

Suggestions are working drafts.

Core has organization AI policy, approved knowledge context and audit reads. In the verified local journey, a simulated model proposed text; the agent edited and approved it, then chose whether to send. Wider retrieval quality, citations, abstention and real provider acceptance remain open.

  • Agent can approve, edit or reject
  • No automatic customer send
  • External AI requires an effective grant and policy
LOCAL QA OBSERVATIONDraft approved

Customer reply still unsent until the agent acts.

Simulated AI response, real Core persistence.
DEPLOYMENT SECURITY

Hosting claims follow hosting proof.

The local stack runs Core, PostgreSQL, S3 compatible storage and a separate worker. A hosted pilot still needs TLS, restore proof, monitoring, a continuously running worker and review of the chosen region and provider setup.

See deployment status