Booking Q4 deliverystart with a free workflow plan Denver · Phoenix · Remote
Security & data handling

Know where your data goes. Know who stays in control.

Review the deployment, data handling, and approval controls before you commit. These are the controls used in MARCUS, the system running at B:Side Capital, and the questions we work through for your own build. Your written scope identifies the deployment and controls that apply to your workflow.

The architectureIn production
ModelsLocal-first
PIIFiltered pre-model
StorageEncrypted at rest
Audit logAppend-only chain
ActionsDefined approvals
01 / The controls

Five controls, in the order your data meets them.

A useful security review follows the data: where it enters, what the model receives, where results are stored, and who can authorize an action. Deployment choices belong in that review before work begins.

C-01

Local models, on your hardware.

For regulated workflows, local models can run on hardware you own. In MARCUS, borrower documents are processed locally; selected tasks can route filtered text to a commercial model. When external processing is appropriate, the data boundary and trade-off are described in the written quote for you to decide.

Deployment: on-prem by default for regulated data
C-02

Personal information is filtered before model processing.

Microsoft Presidio detects supported personal identifiers such as names, Social Security numbers, and account numbers so they can be removed before model processing. Automated detection can miss information. The filter is one control alongside deployment restrictions, access decisions, and tests using known identifiers. Read Presidio’s documented limitations.

Engine: Microsoft Presidio · runs before model ingestion
C-03

Stored documents and work products are encrypted.

MARCUS encrypts stored documents, extracted data, and work products. Encryption helps protect stored information; access to the running system and its keys still matters. Review those responsibilities as part of your deployment.

Scope: all stored documents and derived data
C-04

Every action writes to an append-only, tamper-evident log.

MARCUS records actions in an append-only, hash-chained audit log. The chain makes changes to recorded entries detectable when verified. It provides evidence for a review; it does not replace access control, retention decisions, or an investigation of the underlying action.

Property: append-only · chained · verifiable
C-05

A person signs off on every consequential action.

Consequential actions require human approval. In MARCUS, financial and lending work is prepared for a person to approve, return, or escalate. A customer-facing workflow may handle routine replies or bookings within its agreed scope. The scope must distinguish those actions from decisions that wait for approval.

Rule: the machine prepares; people decide
02 / Before you approve a build

Bring these questions to the review.

  • Deployment. Which work stays local, which can use external services, and what information can cross that boundary?
  • Access. Who can read the records, administer the system, approve actions, and revoke access?
  • Retention. Where are source files, work products, backups, and audit records kept?
  • Decisions. What can run automatically, what needs a person, and where does an exception go?
  • Evidence. What is tested, how are failures reported, and what does an audit-log review establish?
  • Responsibilities. Which controls belong to your team, to Main & Machine, and to a third-party provider?
03 / Not a policy document

This architecture is running right now.

MARCUS supports B:Side Capital, a regulated SBA 504 / CDFI lender led by our founder: 14 AI agents across 7 departments, built from ~840 source documents. It combines local processing, a privacy filter, an audit trail, and human approval of consequential actions. The published results report borrower identifiers sent to an outside model: 0 during the reported measurement window. Read the results and their limits.

Read the MARCUS case study

Have a security questionnaire? Send it, or bring your IT reviewer to the free 30-minute assessment. The person answering is the founder who is accountable for the build — and “that control doesn’t apply to your workflow” is an answer we’ll put in writing too. The plain-English version of the cloud-versus-on-prem call is in where your AI data actually goes.

Book the free assessment →

The guarantee: If a scoped workflow is not live in your operation within 90 days, we keep building at no charge until it is.

The credit: Your audit fee can be credited toward a sprint signed within 60 days, up to 25% of the sprint price.

See the price list →

Fair questions

What compliance asks.

Something we didn’t cover?

Ask it directly. Security questions land with the founder, not a sales queue.

Ask a security question
01Does our data leave our building?

It depends on the agreed deployment. Local processing can keep source documents on your hardware; selected tasks may use external models on filtered text. We describe external processing in the written quote so you can review the data boundary before work begins.

02Do AI models see our customers’ personal information?

A privacy filter detects and removes supported identifiers before processing. Automated detection is imperfect, so we review the data, deployment restrictions, and additional controls for the workflow. Passing a document through a filter is not a guarantee that every identifier was removed.

03How is stored data protected?

MARCUS encrypts stored documents and work products and records actions in an append-only, hash-chained audit log. Your deployment review should also cover access, keys, backups, and retention.

04Can we audit what the system did?

Yes. An append-only, hash-chained log records system actions and supports checking for changes to recorded entries. Your review should establish who can access the log, how it is retained, and how verification is performed.

05Can the AI act on its own?

The scope defines that boundary. Routine replies and bookings can run within agreed rules; consequential actions require approval. MARCUS prepares financial and lending work for people to review and uses systems of record for eligibility, credit, and price inputs.

06Has this architecture run in a regulated environment?

Yes. MARCUS supports B:Side Capital, a regulated SBA 504 / CDFI lender led by our founder, with 14 AI agents across 7 departments. The case is published with permission. Its controls and reported results are evidence of that deployment, not a certification of every future build.