SECURITY & TRUST

Security and evidence boundaries are part of the architecture.

Project intelligence only works if customers can trust how documents, evidence and access are separated.

PROJECT BOUNDARIES

Customer data is project-scoped.

Vánsöll AI is designed so one customer’s project documents and evidence do not become another customer’s project truth.

TRACEABILITY

Evidence stays attributable.

Source documents, revisions, object references and confidence states are retained so important conclusions can be followed back to evidence.

HUMAN AUTHORITY

AI does not become the contractual authority.

Authorised people remain responsible for engineering approval, site decisions, contractual instructions and statutory compliance.

DATA DESIGN

Built for secure cloud storage, not a folder full of loose uploads.

The production architecture separates structured project intelligence from heavy document storage. Metadata, permissions, findings and evidence references belong in the application data layer; large project files belong in controlled object storage with tenant and project isolation.

Production hardening roadmap

  • Authentication and role-based authorisation
  • Tenant and project isolation
  • Encrypted transport and storage
  • Secure object storage and signed access
  • Audit logging, backups and retention controls
  • File validation, malware scanning and rate limiting
AI provider data use: Vánsöll’s intended production integration uses business/API services with organisation data-sharing disabled by default. Customer project data will not be deliberately contributed to shared model training without explicit authorised opt-in. Exact retention and provider controls will be documented at production launch.
Scroll to Top