Skip to main content
Trust Center
AI Safety

AI that respects your data.
Nine layers that prove it.

Every AI feature - Ask TappIQ, autonomous agents, Content Studio - goes through the exact same set of protections. Nothing is exempt, and no shortcut skips a single layer.

Defense in Depth

The nine-layer AI trust boundary

Each layer is enforced independently, so getting past one does not weaken any other. They all run on every AI request, every time.

01

Input Guard

Every request is checked against clear rules for what AI is allowed to do. Anything outside those bounds is refused and logged before the AI model ever sees it.

02

Manipulation Detection

Every input is screened for attempts to trick the AI into ignoring its rules. Clear attempts are blocked; borderline cases are slowed down and logged for review.

03

Organization Isolation

Any attempt to reach another organization's data is refused immediately - nothing is returned. Even a TappHQ administrator's support access requires short-lived, single-purpose approval that expires quickly.

04

Untrusted-Source Tracking

Content that comes from outside sources - incoming emails, automated messages, uploaded documents, or saved notes - is flagged as untrusted. Any action based on that content requires your explicit approval before anything is saved.

05

Field-Level Data Limits

Each AI tool can return only a specific, pre-approved set of fields. Everything else is removed before the AI sees it, so no extra data is ever exposed by accident.

06

Sensitive-Data Screening

Every AI response is scanned for sensitive data like credit card numbers, Social Security numbers, passwords, and access keys. Anything found is automatically redacted, and responses carrying too much sensitive data are blocked entirely.

07

Safe Links & Content

Links the AI includes in its responses are restricted to trusted destinations, and any formatted content is cleaned so it can't carry hidden or malicious code.

08

Leak Detection

Untrusted content is invisibly watermarked. If any of those markers ever show up in an AI response, it's a signal that something leaked - and a security alert fires immediately.

09

Whole-Conversation Protection

If a conversation is ever flagged as suspicious, the extra safeguards stay in place for the rest of it. Actions require added confirmation, and anything saved during that conversation is kept out of future AI results.

Data Commitment

Your data never trains a model.

Our primary AI provider (Anthropic) operates under a zero-retention commercial agreement: your prompts and the AI’s responses are not stored, not used for training, and not accessible to human reviewers outside narrow abuse-response circumstances governed by their published policy.

Zero data retention with Anthropic
No training on customer prompts
No telemetry data sales
No internal model training on your data
Published DPA with every AI vendor
Audit log of every AI call

You take responsibility for any BYOK key you mark as ZDR. TappHQ and our providers have no visibility into your agreements with your providers. By using BYOK, and bypassing our ZDR policy, you understand that data retention with your providers is at your own risk.

Your Controls

You stay in control

Safety defaults are on. Every guard can be tuned or audited by your platform admins without opening a support ticket.

Per-Agent Safety Levels

Strict / Standard / Permissive (Enterprise). Adjust how strict the safety controls are on any individual agent without affecting others.

Org-Level Link Allowlist

Add your own trusted domains for links the AI includes. Any link to a domain you haven't approved is removed before the response reaches users.

Refusal Telemetry

See which requests were refused and why, and whether your organization is nearing the alert threshold for refused requests.

Alert Preferences

Weekly digest or immediate notification for high-confidence injection attempts. Route alerts to your security team directly.

Kill Switches

Every defense has a setting toggle for emergency bypass. All toggles require platform-admin role and are logged to your immutable audit trail.

Full Audit Trail

Every AI request, every action, every refusal, and every approval is logged with full context, and the log is hash-chained so any tampering is detectable.

AI Vendors

Every AI vendor, disclosed

Every vendor TappHQ uses for AI processing, their purpose, data retention policy, and DPA status - no surprises.

AI vendors used by TappHQ
VendorPurposeRetentionRegionDPA StatusLinks
AnthropicThe AI models (Claude) behind Ask TappIQ, AI agents, Content Studio, and our content-safety screening.No retention. Your prompts and the AI's responses are not stored by Anthropic under a zero-retention commercial agreement.United StatesSignedDPA →Subprocessors →
Vercel AI GatewayRoutes AI requests to Anthropic and other model providers, with automatic retries and failover for reliability.Basic request information retained 30 days for monitoring; message content is not retained.United States, European UnionSignedDPA →Subprocessors →
Voyage AIPowers search and content matching across your knowledge base.No long-term retention. Results are returned and not stored by the vendor.United StatesSignedDPA →
UpstashShort-lived counters that enforce rate limits and AI usage budgets.Temporary only. Data expires within seconds to a day; nothing is kept long-term.United States, European Union (replicated)SignedDPA →Subprocessors →
Trust Center

Questions about our AI posture?

Procurement teams can request our full AI security review packet, vendor DPAs, and architecture overview. No NDA required for the overview.