Security and trust

Your data, your boundary. Decided with you.

Most AI vendors hand you a fixed architecture and ask you to accept it. We do the opposite. Where an agent runs, which models it uses, what it can reach, what it may do alone and what is kept afterwards are all configurable, and they are configured with you during solution design, before an agent touches real work.

This page is the control surface. Bring it to your procurement team.

The control surface

Six decisions, and you make them.

None of these are defaults we impose. Each is set during solution design and written into the engagement, so what you agreed is what runs.

Where it runs

Agents can run on infrastructure we own and operate, inside your own cloud tenancy, or on your own hardware. Australian hosting is available for every option.

Who decides

Decided during solution design, before an agent touches real work

Which models it uses

Private and self-hosted models, commercial API models, or a mix chosen per task. Where a task can run on a private model, it can be configured to run only on a private model.

Who decides

Chosen per task, and written into the design

What the agent can reach

An agent only reaches the systems you have connected, with the permissions you have granted. Scope is explicit rather than inherited, so it cannot quietly widen.

Who decides

You grant each connection

What it may do alone

Every action is either autonomous or approval-gated, set task by task. High-stakes actions can stay approval-gated permanently, no matter how accurate the agent becomes.

Who decides

New agents start fully supervised

What is kept, and for how long

Retention for inputs, outputs and logs is configured per engagement. Where a workflow requires that nothing is retained beyond the task, that can be configured too.

Who decides

Set with you, and documented

What you can see afterwards

Every action the agent takes is logged: what ran alone, what waited for approval, who approved it and why it was escalated. The audit trail is yours to inspect.

Who decides

On by default

Why we build it this way

We own the stack underneath.

A large share of what is sold as AI implementation is a thin layer over somebody else's API. That is fine until a client asks where their documents went, or wants a model to run somewhere specific, or needs an answer that does not begin with "our provider says".

Because we build and run the infrastructure ourselves, private and self-hosted deployment is a configuration choice rather than a special request we have to escalate. For document-heavy and compliance-sensitive work, that is usually the whole conversation.

Private by configuration

Where a task must run on a private model, it can be configured to run only on a private model.

Onshore available

Australian hosting is available across the deployment options, not as an exception.

Inspectable

Every action logged, every approval attributable, every escalation visible.

Procurement questions

Answered before you have to ask.

Does our data train anybody's model?

Not as part of how we build. Where a private or self-hosted model is used, your data does not leave the environment it runs in. Where a commercial API model is used for a task, the provider and its terms are named in the design, so you can accept or reject that specific choice rather than discovering it later.

Can everything stay in Australia?

Yes. Hosting region is one of the decisions made during solution design, and Australian hosting is available across the deployment options. If onshore-only is a requirement, say so at the scoping call and it becomes a constraint on the design rather than a question at the end.

What happens when the agent gets something wrong?

Guardrailed actions cannot leave the boundary you set. Anything unusual escalates to a person rather than proceeding, and every action is logged, so a mistake is visible, attributable and reversible. Supervision is the default for exactly this reason.

Who at NorthCape can access our systems?

Access is granted per engagement and limited to the people delivering it, which in practice means the founders and anyone explicitly named. Access can be scoped, time-limited or removed at your request, and we will document what was granted.

Do you hold any certifications?

We do not currently advertise formal certifications, and we would rather tell you that plainly than imply otherwise. What we can do is answer a security questionnaire, work to your own security requirements, and document the design decisions above so your procurement process has something concrete to review.

What if we want to stop?

An agent can be switched off without unwinding the systems it plugged into, because it works alongside your tools rather than replacing them. Pilots are fixed-scope and end with a keep-or-kill decision, so stopping is a normal outcome rather than an exit process.

Still have a question?

Bring it to the scoping call. If the answer is no, you will hear no.