No AI at run time
Steps compile once into deterministic code and test runs hold no AI credentials. No model call can happen inside a run.
Your security team sets where AI may run, which model and region it uses, and who approves. Every action is recorded and ready for audit.
| Scope | AI policy | Model and zone |
|---|---|---|
| Retail | Generate with approval | Azure OpenAI, EU data zone |
| Claims | Suggest only | Amazon Bedrock, US region |
| Payments | Off | None. No model call possible. |
| Reporting | Suggest only | Local model |
Steps compile once into deterministic code and test runs hold no AI credentials. No model call can happen inside a run.
The author of a test, heal or AI draft is never its sole approver. That holds for people and agents alike.
AI permissions grow only on evidence and drop back automatically when a rule is breached.
Each scope gets one setting, so a regulated line of business and an internal tool follow different rules on one platform.
Administrators decide how far AI may go in each scope. Approving a heal always stays with a person.
Access works the way your identity team already runs it, and is denied by default.
Data is encrypted in transit with TLS and at rest. Prompts and outputs stay in the residency zone you pin each scope to.
Every action is recorded with who, what, when and why, and exports to your SIEM.
Email contact@qventis.ai with "Security" in the subject. We acknowledge your report, keep you updated and ask for reasonable time to fix before disclosure.
Yes. Set its policy to off. With no model configured, no model call is possible.
Yes. Ask during your evaluation and we walk your security team through it.
We walk your team through AI policy, approvals and audit on your own scenarios.