Security & data

Your business data, treated like it matters

Farm financials are among the most sensitive records a business holds. Here is how Aidvisor stores them, who can reach them and what we will never do with them.

The commitments

Four things we will not compromise on

You control access

You decide who joins your organisation and which projects an advisor can reach. Access is explicit, and revocable the moment you want it gone.

Never used for training

Your data is not used to train public foundation models, and is not pooled with other customers to build shared models.

Scoped on every request

Organisation and project scope is enforced at the backend on every agent call. Out-of-scope requests are rejected, not filtered.

Read-only by design

Our AI agents have no write access to your connected systems. Aidvisor advises; it never changes a record on your behalf.

Tenancy

Isolation that holds under pressure

The hardest problem in multi-tenant AI is stopping one customer’s data from surfacing in another customer’s answer. We solved it at the architecture level rather than the prompt level, because prompts are not a security boundary.

  • Every organisation is a distinct tenant with its own data boundary
  • Every agent tool call must carry an organisation and project scope
  • Requests with missing or mismatched scope are rejected at the backend
  • Advisor access is project-scoped, explicit and revocable
  • Cross-project data access attempts are blocked and logged

Access model

Organisation roles

Owner, Admin, Member and Viewer — scoped to your organisation and evaluated on every request.

Advisor access

Cross-organisation but project-scoped. Granted deliberately, revoked instantly.

Multi-factor authentication

Available to all users and mandatory for our own platform administrators.

Controls

How the platform is protected

Encryption

Data is encrypted in transit with TLS and at rest in both the database and document storage.

Least privilege

Internal access is role-based, granted on need and logged. Platform administrators must use multi-factor authentication.

Audit trail

Authentication events, access grants and administrative actions are recorded so questions about access have answers.

Managed infrastructure

Hosted in Singapore on established managed providers with their own hardened operational practices, rather than servers under a desk.

Incident response

A defined process for identifying, containing and communicating security incidents — including telling you promptly if you are affected.

Data portability

Export your documents and records whenever you want. No hostage-taking, no exit fee for leaving.

Where we are honest with you: Aidvisor is an early-stage platform. We are working toward formal security certification rather than claiming it today. If your IT or risk team wants to review our architecture, controls and roadmap in detail, we will make time — get in touch.

AI specifics

What happens to your data when you ask a question

When you ask Aidvisor something, relevant passages from your own documents are retrieved and sent — along with your question — to a large language model to generate the answer. That means:

  • Only the passages relevant to your question are included, not your entire document set
  • Model providers are contractually restricted from training on data sent through our platform
  • The retrieved context is scoped to your organisation and project before it ever leaves our backend
  • Answers are returned with citations so you can verify what was drawn from where
  • Chat history is retained in your organisation so you can audit what was asked and answered

Questions

Security FAQ

Is my farm data used to train AI models?

No. Your documents and data are not used to train public or third-party foundation models. They are used to answer your questions, within your organisation, and nothing else.

Where is my data physically stored?

Our database and document storage are hosted in Singapore with established cloud providers. If your organisation has specific data residency requirements, talk to us — we are happy to go through the detail with your IT or risk team.

Can Aidvisor staff see my data?

Access by our team is restricted to platform operations and support, is granted on a least-privilege basis, and is logged. We do not browse customer data, and support access to a specific organisation is undertaken only where it is needed to resolve an issue.

What happens if I stop using Aidvisor?

Your data remains yours. You can export documents and records at any time, and we will delete your data on request in line with our privacy policy.

Do you hold security certifications?

We are building toward formal certification and are happy to discuss our current control set, architecture and roadmap directly with your IT or risk team. We would rather tell you exactly where we are than imply a certification we do not yet hold.

Bring your hardest questions

We would rather have the data-handling conversation up front than discover it matters later. Ask us anything.