ContourIQ
Security & trust

AI inside your business, on your terms.

The questions below are the ones owners actually ask before connecting AI to their operations. Straight answers, no badge theater.

Common concerns

Asked and answered.

Scope note: This overview describes design practices, not a certification, compliance opinion, or guarantee. Before launch, the engagement should document vendors, data flows, retention, access, logging, recovery, incident handling, and deletion responsibilities for the actual workflow.

Is my business data safe?

No platform can promise zero risk. Axiom workflows are designed around scoped credentials, minimum necessary access, revocation, separation between businesses, and logging where the connected systems support it. Exact controls are documented for the selected architecture.

Does AI have access to all my private data?

It should not. Each workflow is configured around approved sources and minimum necessary access — for example, a content workflow should not receive accounting data. The audit maps the intended data flow before credentials are connected.

Do you train AI models on my data?

ContourIQ does not use client business data to train its own models. Processing by an external AI provider depends on the selected vendor, account type, settings, and current contract terms; those dependencies must be reviewed and documented for the engagement.

Can sensitive data stay local?

Some sensitive data can remain inside systems you control when the workflow and connected tools support that boundary. Other integrations or model calls may require external processing, so residency and transfer requirements are confirmed before implementation.

Can Axiom run locally on a business-owned computer?

Certain components may be eligible for local or private deployment. Not every integration, model, or support process can run entirely on one business-owned computer, so feasibility and operational responsibility are scoped case by case.

Do you sign NDAs?

Yes. An NDA is available before we ever look at your systems or data.

Who owns the customer data?

The business retains ownership of its source records. The engagement documents which derived records are created, where they live, available export paths, credential revocation, and the agreed deletion or retention process at offboarding.

How are employee permissions handled?

Roles and approval responsibilities are defined per workflow. The exact enforcement depends on Axiom and the permissions exposed by each connected system, so access tests are part of implementation rather than an assumed guarantee.

Can AI take actions automatically?

Only where the workflow, connected system, and permissions allow it. A cautious implementation can begin with approval required, then consider bounded low-risk actions after testing and review.

Can actions require human approval?

Yes — approval-first is the default design posture for sensitive actions. Pricing, contracts, outbound content, and money-touching actions can wait for a designated person to approve, edit, reject, or escalate them.

How does Axiom reduce risk when implementing AI?

The design starts with one workflow, defines approval and stop conditions for consequential actions, and records activity in Axiom or connected systems where supported. The implementation also documents residual risks and who owns each escalation.

Security models

Matched to your sensitivity, not one-size-fits-all.

The proposed Axiom architecture depends on what the workflow handles, which tools must connect, and who owns each control. A landscaping company and a law firm do not need the same posture. Eligible components may be scoped for local or private deployment; vendor and operational limits remain explicit. NDA available.