Last updated: 2 August 2026

Failsafe is designed with customer control at its core. Security, access, hosting and retention requirements are agreed for each deployment with the customer's security and IT teams.

Data security and customer control

Failsafe is designed to keep customers in control of their data, access permissions and approved actions. Security requirements are defined with each customer and reflected in the deployment design.

Regional hosting and retention

Customer data is designed to be hosted in the region agreed with the customer. Data is retained according to the approved customer retention policy.

Encryption

Customer data is designed to be encrypted in transit and at rest.

Controlled access

Access is designed around role-based access controls. Where supported, permissions are inherited from connected source systems so users only receive access to information they are authorised to access.

Read-only integration by default

Connections to source systems are designed to be read-only by default. Any write action must be separately authorised and controlled by the customer.

Model-training policy

Failsafe will not use customer data to train shared AI models or shared Failsafe agents.

Human approval and customer control

Accountable customer personnel retain control over decisions and approved actions. Failsafe is designed to support review without replacing customer approval responsibilities.

Security review

Deployment, access, hosting and retention requirements are agreed with the customer's security and IT teams for each deployment.