SECURITY
Built for scrutiny.
Security and control are not features added to Balau AI—they are the architecture. Context is permission-scoped, actions are human-controlled, and evidence is kept by default.
What follows are the answers a security questionnaire asks for: how firms are isolated, how data is encrypted, what the record keeps, what the AI sees, and how to reach us with a finding.
- PERMISSION-SCOPED
HUMAN-CONTROLLED EVIDENCE BY DEFAULT
Four commitments.
01
Permission follows firm roles.
Access is resolved from the firm’s user roles and permissions at the moment of use—not maintained as a separate AI permission layer.
02
Outputs carry their sources.
Summaries, drafts, and answers come with references to the material behind them, ready for inspection.
03
Consequential changes require human approval.
Consequential changes and anything leaving the firm pass through a named human approval.
04
Access and activity evidence is preserved.
Who saw what, when, and what was approved—retained and reconstructable.
ARCHITECTURE
How the platform is built.
Four properties of the system, stated plainly enough to paste into a questionnaire. They describe what holds, not which products it is built from. Implementation detail belongs in the documentation pack, where a reviewer can read it under an NDA.
The record behind an AI-assisted output looks like this. It also names the provider and the model that handled the call, which is not reproduced here for the same reason nothing else on this page is.
Append-only — entries here cannot be modified once recorded.
Aug 20, 2026 at 11:03 PM
AI output generated
system · success- Task
- compose-daily-brief
- Prompt version
- v5
- Served from cache
- No
- Tokens in
- 2,696
- Tokens out
- 303
- AI output reference
- 01a022ea-6a94-7e35
Redactions (3 total)
- Names anonymized
- 3
TENANT ISOLATION
How is one firm’s data kept separate from another’s?
Every customer firm is a separate logical tenant. Database-level Row-Level Security is enforced on every table, and the query layer requires an explicit tenant scope on every call, which Row-Level Security then enforces at the database.
ENCRYPTION
How is customer data protected at rest and in transit?
Customer data is encrypted at rest under per-tenant AES-GCM envelopes, so each tenant’s data is cryptographically bound to its own key, and in transit via TLS 1.3. Keys are managed under cloud-native key management with separation between key-encryption and data-encryption keys. Operator access to plaintext is auditable end-to-end.
APPEND-ONLY AUDIT LOG
What is recorded, and can the record be changed afterwards?
Every sensitive action (read, write, delete, AI dispatch, sub-processor routing) writes an audit record. Append-only enforcement lives at the database layer; no application-side role has permission to modify or delete rows. Audit records are retained for seven years. The firm remains the record-keeper of obligation.
AI DATA HANDLING
What does the AI see, and what leaves the firm?
Personal identifiers are redacted before content reaches a model: identifiers are stripped on every path, and named individuals are tokenized on the context-packet path (enforced by the type system at compile time), on the daily brief, and in the conversational assistant’s tool results. One gap is open and recorded in the assistant’s impact assessment: a name a person types into the assistant that no tool result returns is not yet tokenized, and neither is such a name carried forward from an earlier turn. On the context-packet path, signature blocks are also stripped and per-tenant patterns can be added. AI provider contracts include zero-retention commitments. The per-task model inventory and the redaction rule set are visible live in the product’s AI policy settings and are provided during procurement review.
OPERATIONS
How it is run.
Where the data sits, how long it is kept, who can reach it, who else processes it, and what happens on the day something goes wrong.
What that looks like when someone asks for something they are not cleared to see:
summarize the documents
I don’t have permission to access uploaded documents on your behalf. To view and summarize documents, you’ll need your admin to grant the documents:read permission to your account.
Is there something else I can help you with, perhaps information from communications, customer records, or action items?
Balau AI surfaces information from your records, not investment, legal, or suitability advice. Verify with your records before acting.
DATA RESIDENCY
Where does customer data live?
Customer data is stored and processed in the United States, and the third-party services that process it on our behalf operate in United States regions. Balau AI is a US company serving US firms, so US law is the governing regime and US state privacy law is the primary privacy framework we work to.
RETENTION
How long is data kept, and can it be deleted?
Retention is defined rather than open-ended. Audit records are retained for seven years. Retention windows for customer content, and the deletion and export paths available to a firm, are set out in the customer contract and are provided on request during review. Customer data is never used to train models.
ACCESS CONTROL
Who can see a firm’s data?
Inside the product, access is resolved from the firm’s own user roles and permissions at the moment of use, so there is no second AI permission layer to configure, sync, or reconcile. Answers, summaries, and drafts are built only from material the person asking is permitted to see. On our side, access follows least privilege, and operator access to plaintext is auditable end-to-end.
INCIDENT RESPONSE
What happens if something goes wrong?
Suspected incidents are triaged on receipt, and incident response is a documented part of the security program rather than an improvised one. The append-only audit log is what makes reconstruction possible: what was accessed, by whom, and when. Affected customers are notified in line with their contract and with applicable US state breach-notification law.
Report a suspected incident to security@balau.ai.
YOUR OWN AI PROVIDER
Can a firm run AI under its own provider account?
Yes, for the calls that produce answers, summaries and drafts. A firm that already holds its own contract with any of the AI providers this product supports can connect that account, and those calls are then made under the agreement its own compliance team has already reviewed. The provider bills and logs the firm rather than us, so the principal in the provider’s own records is the firm itself. For those calls we are a conduit rather than the counterparty: the provider is the firm’s processor under the firm’s agreement, not one of ours. A firm can also make this mandatory, in which case such a call that cannot use the firm’s own credentials fails rather than falling back to ours. Building the search index that makes a firm’s own material findable is a separate path that this does not cover and that still runs under our provider account. Which providers can be connected, and which one a firm’s calls currently run on, are both shown in the product’s own settings rather than confirmed with us first. Connecting a provider account is available on our Professional plan and above.
SUB-PROCESSORS
Who else touches the data, and how would we hear about a change?
Third-party services that process customer data on our behalf receive only the data their purpose requires, and providers of AI capability receive prompts with personal identifiers redacted, under zero-retention commitments. The current inventory, with the purpose and processing region of each entry, is provided during procurement review and alongside the customer contract rather than published here. Customers on the change-notification list receive 30 days’ advance notice before a sub-processor is added, removed, or has a material change of scope.
Subscribe to change notices by emailing trust@balau.ai with the subject “Subscribe to sub-processor change notices.”
PROGRAMS
Independent scrutiny,
in progress.
SOC 2 Type 2 and ISO 27001 programs are in progress. Documentation of our posture, sub-processors, and practices is available to prospective customers on request.
Status and document list reviewed 30 September 2026
Encryption in transit and at rest.
Tenant isolation by design.
Least-privilege access.
Defined retention; data never trains models.
Personal identifiers redacted before AI processing.
DILIGENCE
What can you send our compliance team?
Email trust@balau.ai with the documents you need, and we reply with our mutual non-disclosure agreement for counter-signature. Everything below is released under that NDA rather than published, and the status beside each document says whether it exists today. Security questionnaires go to security@balau.ai.
SOC 2 Type 2 report
Not yet available
Available once the first attestation completes. The SOC 2 Type 2 and ISO 27001 programs are in progress; until a report or certificate is in hand we claim neither.
Threat models and Data Protection Impact Assessments
Available under NDA
Structured threat models and impact assessments for the load-bearing surfaces of the platform, including the surfaces where AI touches customer material.
Compliance posture snapshot
Available under NDA
A cross-framework review of our control posture, refreshed at minimum quarterly, so a reviewer sees the current state rather than a launch-day snapshot.
Data processing agreement and sub-processor inventory
Provided with the contract
The data processing agreement every customer signs, and the current sub-processor inventory with the purpose and processing region of each entry.
DISCLOSURE
How do I report a vulnerability?
Send the report to security@balau.ai with reproduction steps and any artifacts that help us confirm the finding. Security research is welcome here, and a finding reported in good faith is treated as a contribution rather than a nuisance.
INITIAL RESPONSE
Within five business days of the report reaching us.
TRIAGE AND REMEDIATION
A timeline is communicated once we have reproduced the finding, paced by severity, with critical findings prioritized same-week.
SAFE HARBOR
Good-faith research conducted within the scope below is welcome. We ask that researchers do not access, modify, or exfiltrate customer data, and that they coordinate disclosure with us before publishing.
SCOPE
All production surfaces under balau.ai and app.balau.ai. Out of scope: denial-of-service testing, social engineering of employees, physical attacks, and third-party sub-processors, which should be reported upstream.
CONTACT
Who should we write to?
Three inboxes, so a request reaches the right desk without a handoff.
Privacy
Privacy requests, CCPA and US state-privacy inquiries, and questions about our processor relationship.
Security
Vulnerability reports, suspected incidents, and security questionnaire follow-ups.
Trust and compliance
Confidential-document requests, NDA execution, and compliance questions.