Last updated: 2 August 2026
Failsafe is designed with customer control at its core. Security, access, hosting and retention requirements are agreed for each deployment with the customer's security and IT teams.
Data security and customer control
Failsafe is designed to keep customers in control of their data, access permissions and approved actions. Security requirements are defined with each customer and reflected in the deployment design.
Regional hosting and retention
Customer data is designed to be hosted in the region agreed with the customer. Data is retained according to the approved customer retention policy.
Encryption
Customer data is designed to be encrypted in transit and at rest.
Controlled access
Access is designed around role-based access controls. Where supported, permissions are inherited from connected source systems so users only receive access to information they are authorised to access.
Read-only integration by default
Connections to source systems are designed to be read-only by default. Any write action must be separately authorised and controlled by the customer.
Model-training policy
Failsafe will not use customer data to train shared AI models or shared Failsafe agents.
Human approval and customer control
Accountable customer personnel retain control over decisions and approved actions. Failsafe is designed to support review without replacing customer approval responsibilities.
Security review
Deployment, access, hosting and retention requirements are agreed with the customer's security and IT teams for each deployment.