Security & Responsible AI

Enterprise AI built on trust.

Every response grounded in your verified content. Every decision traceable to its source. Zero data retention. Complete governance control. Your data never trains our models.

Compliance status list showing SOC 2 Type 2, GDPR, data retention, and model training all checked as compliant.

Three pillars

Responsible
AI, by design.

Our commitment to building AI that serves teams without compromising trust or control. These aren't features. They're the floor.

01

Transparency

Every response shows exactly which documents it came from. Confidence scores, editable drafts, and full version history, so your team always knows what the AI did and why.

02

Human-in-the-Loop

AI handles drafting. Your team handles the final call. Every response is reviewed, edited, and approved before anything reaches a buyer.

03

Enterprise-Ready Governance

Role-based access, permission controls, content expiration, and tenant isolation built in from day one. Iris fits the way enterprise teams actually work.

In practice

See these
principles in action.

Every principle is backed by real functionality you can see, control, and audit. Here's how transparency, human oversight, and governance work day to day.

Smart flagging

Focused reviews, not over-editing.

Iris flags responses it's uncertain about, so your team focuses time where it matters. No over-editing. No risky content slipping through.

  • See what needs review, low-confidence answers are automatically flagged
  • Skip what's solid, high-confidence responses are clearly marked
  • Focus SME time on what actually matters, and speed up approvals
Confidence scoring list showing SOC 2, uptime SLA, EU data residency verify, and SSO via SAML with percentages.
Screen showing a 'source-of-truth trace' with SOC 2 Type II certification answer and related document links.

Zero data retention

total transparency.

Your data never leaves your environment. Iris doesn't train on your content, doesn't share it with other customers, and doesn't expose it to external models. What goes in stays yours.

  • No LLMs train on your data. Ever. Contractual, not aspirational
  • Source transparency, see which docs powered each response
  • Traceable outputs, every answer linked to its exact source
  • Content control, only approved, permissioned documentation

Custom instructions & templates

Set it once,
enforced everywhere.

Set your tone, structure, and compliance standards once. Iris enforces them on every response, no rewriting from scratch, no brand inconsistency, no compliance gaps.

  • Brand consistency, automatic tone and style enforcement
  • Compliance templates, pre-built structures for regulatory requirements
  • Custom workflows, tailored approval processes for your team
  • Version control, track changes and maintain document history
Instruction Wizard showing checkboxes for Tone, Length, Differentiators, and Compliance template options.
Activity log showing edits, approvals, and exports with timestamps from 2 minutes to 1 hour ago.

Full revision history

Audit-ready, not scrambling.

Every action logged, every change timestamped, every user tracked. When a compliance audit hits, you're ready, not scrambling.

  • Complete audit trail, every action logged and timestamped
  • User tracking, see exactly who made each change
  • Export capabilities, generate compliance reports instantly
  • Real-time monitoring, live dashboard of all system activity

Enterprise-grade

Security you can trust.

Your data never leaves your environment. Tenant-isolated. Encrypted in transit and at rest. SSO, SCIM, and audit log export from day one.

0%

Data retention

100%

Traceable to approved sources

24/7

Monitoring

360o

Audit trail

Our commitment to responsible AI

“At Iris, responsible AI isn't just a feature. It's a mindset. We audit model behavior, listen to user feedback, and evolve with the latest research and enterprise needs. Our goal is to give teams the confidence to adopt AI knowing they have transparency, governance, and human oversight at every step.”

Ben Hills, CEO, Iris

Trust FAQ

The questions
your CISO will ask.

How Iris handles your data, your IP, and your AI exposure, answered without the marketing varnish.

Does Iris train on our data, or use it to train external models?

No. Your workspace is fully tenant-isolated, and your data is never used to train external or shared foundation models. Contractual, not aspirational.

How does Iris protect sensitive or regulated information?

Strong access controls, workspace-level permissions, and content visibility settings let teams restrict who can view or use specific knowledge. Sensitive material never leaves your environment or becomes available to other customers.

Can we control which content the AI can access?

Yes. Admins manage which libraries, documents, and knowledge sources are available to Iris on a per-source, per-team basis. You stay in strict control over how content is used during retrieval and generation.

Does Iris require human review before responses go out?

Yes. AI provides speed and structure, but humans control validation and approval. Routed approvals enforce the workflow your governance team already requires, so outputs meet policy, tone, and compliance standards before they reach a buyer.

How is transparency enforced in AI-generated answers?

Iris shows which sources and knowledge informed every draft, including section, version, and timestamp, so teams can trace any response back to approved content. It supports auditability, compliance reviews, and clear oversight of AI-assisted work.

What about pen tests, SOC 2 reports, and DPAS

SOC 2 Type II report, annual third-party penetration test reports, GDPR DPA, and our security architecture overview are available under NDA. Reach out and we'll send them within the day.

Trust

Secure AI at enterprise scale.

Talk to our team about deploying Iris in a way that meets your security, legal, and procurement bar.