AI moves the work forward.
You stay in control.

Permissions, approval policies and isolation govern every action. OccamIQ keeps control with your team and makes the work traceable, from request to result.

AI actions

Your policies govern AI actions
The assistant uses machine output, documents and requests as context. Those sources cannot grant access or authorize a change: server-side permissions and action policies govern execution.
Rules that AI cannot override
Fixed policy rules check every proposed action before AI review. An explicit denial blocks execution; AI review can require additional scrutiny.
Approval shows the exact change
When Policy requires review, the approver sees the commands that will run. What is approved is what executes.
The assistant has your access, no more
The AI works as the person using it, inside their access rights. It has no administrator identity of its own.

Isolation

Organizations are separated in the database
PostgreSQL row-level security limits every read and write to what the signed-in person may access. Application code, search and the AI all go through it.
Platform scripts run in a sandbox
Server-side scripts run in a separate private service under gVisor: read-only filesystem, no credentials, strict resource limits, no public network entry.
Endpoint agents connect out
The endpoint agent enrolls with a single-use token and keeps an outbound encrypted connection. No inbound ports.

Identity and audit

Account access you control
Your administrator invites people into the platform. Multi-factor authentication protects sign-in, and self-service password reset helps people regain access.
Changes have a traceable record
Changes and their audit records are written together in the same transaction. AI actions are identified and attributed to the person they acted for.
Product documentation stays inside
The API reference and product documentation are available to customers after signing in to OccamIQ.

Hosting and data

Located in France
OccamIQ runs on Scaleway in Paris. Documents are kept in private, encrypted, versioned object storage in the same region.
Backups are proven, not assumed
Every database backup is test-restored and checksum-verified before it counts.
Processors are listed per deployment
The AI model provider is agreed with you, EU-hosted included. Before onboarding, you get the list of every processor that handles your data.

Reporting a vulnerability

Found a security issue? Tell us through the contact form and choose “Something else”. Describe the issue and how to reproduce it. Leave out any data that is not yours.

Give us reasonable time to fix it before you disclose it, and do not touch other people’s data while testing. Our contact details are also in security.txt.