aiversum
Security

Who made the decision, what the agent saw, what it must not touch.

Five boundaries, each written into code or into the machine configuration. We answer with mechanisms, not with a compliance declaration. This page is meant to be forwarded to the board.

Book a demo
Five boundaries
01
Live at a client

Data does not leave your environment

The language model is Azure OpenAI in your tenant, with a managed identity, no API keys. The machine and storage sit in the Poland Central region, in your subscription, with no public address. There is no step at which correspondence reaches us.

Enforced by: the client's subscription and tenant, a managed identity instead of a key, no public address on the machine.

02
Live at a client

The agent has no console

CRM access goes exclusively through seven named tools. All of them run parameterised reads. There is not a single write, update or delete instruction.

Enforced by: a mediating server with the list of seven tools in code, each running only a parameterised read. The reason is in a design comment: the agent reads emails from unknown senders.

03
Live at a client

A human at the end of every outbound path

The agent prepares a draft. The system sends only after a customer-service employee approves the draft. The agent does not silently resolve conflicting facts: it marks them and hands them to a human.

Enforced by: a draft has no outbound path without operator approval in the panel. The approval goes to the log together with who performed it.

04
Live at a client

Identity and access

Panel sign-in through your company's Microsoft Entra ID. The panel is encrypted with a certificate from your internal PKI. The panel shows only the knowledge base and drafts; the rest of the resource is hidden.

Enforced by: the client's Entra ID in front of the proxy, a certificate from the client's PKI, Microsoft Defender on the machine.

05

A trail that settles disputes

Engine log: every session, tools used, model. Panel log: who, when and on which file performed an operation. In a dispute with a customer about a reply, the log says who approved it and when.

Enforced by: both logs run at the client.

Three things that make an agent dangerous

Access to private data, content from strangers and the ability to send outbound.

Simon Willison called this combination the lethal trifecta in June 2025. An agent with all three at once can be exploited by a single crafted email. That is exactly how EchoLeak worked in Microsoft 365 Copilot (CVE-2025-32711, June 2025): one message pulled data out of SharePoint without a click.

  • Private data: the agent has access, but read-only and only through named tools.
  • Content from strangers: the agent reads email from unknown senders, so it reaches the CRM only through named read-only tools.
  • Outbound sending: starts only after a human approves. The approval is in the log.

In December 2025 OWASP published a top-ten list of risks for agentic applications. Tool control, agent identity and privilege abuse are separate entries on it.

What IT gets on paper

Before the first access to data.

  • Data flow: where the agent reads from, where it writes, what reaches the model.
  • Scope of permissions: the tool list, what the agent cannot do and where that is written down.
  • Scope of the log: which events, with which identity, who can access it.
  • Division of responsibility: what is ours, what belongs to your IT, what belongs to the process owner.
AI Act, NIS2, KSC

Where the data is, who decides, what is in the log.

Poland's amended cybersecurity act has applied since spring 2026. The AI Act transparency duties have applied since August 2026. Your compliance team gets material: where the data is, who decides, what is in the log, what scope the agent has. The compliance assessment is yours.

When the agent gets it wrong

The agent does not send without a human and does not write to systems. An employee decides.

The log shows who approved the reply and when. Conflicting facts are marked by the agent, not resolved. The vendor's responsibility for the engine and the client's for the decision are described in the offer, before the first access to data.

Ask about any of the five boundaries.

In the demo we show them on the running panel, not on a slide.

Book a demo