VERSIDON

Security & controls

Built to be examined, not just demonstrated.

Evidence you can open, entitlements you already maintain, models under a registry, and one record of every action — human and agent alike. Written for the CISO, the model-risk reviewer and the head of internal audit.

  • Your tenant is the boundary

    Documents and the indexes derived from them stay inside your tenant, and no customer data is used to train a model.

  • Permissions enforced at query time

    Entitlements are inherited from your source systems and applied when the question is asked, not cached at index time.

  • Every claim opens to its source

    Each figure links back to the passage it came from, in the document it came from, for the person who has to sign.

  • One record of every action

    Human and agent actions land in the same immutable log — actor, entity, workspace and timestamp — exportable for examination.

SOC 2 TYPE II · ISO 27001 · GDPR · DATA RESIDENCY BY REGION

Commitments

Six commitments, and how each one is kept.

The sections that follow are the mechanics behind these six. Each one is a property of the platform rather than a setting an administrator has to remember to switch on — set out for the people who have to sign off, and for the reviewers they bring with them.

Your tenant, your boundary

Documents and derived indexes stay inside your tenant. Versidon does not train on your data, and no customer data crosses into a shared model.

Permissions inherited, enforced live

Entitlements come from your existing systems and are applied at query time. If someone cannot open a document in the source system, it cannot reach their answer.

Segregation of duties preserved

Initiator, reviewer and authoriser stay distinct. Agents hold their own least-privilege identity and never inherit a person's approval rights.

Every action on the record

Human and agent actions land in the same immutable log — actor, entity, workspace and timestamp — retained for seven years and exportable for examination.

Models under governance

A registry of every model approved for regulated use, with validation status, owner and review date. Unapproved models cannot be called.

Evaluated before release

Agents are tested against labelled cases and blocked from publish when a suite falls below its threshold. Versions roll back in one step.

How evidence works

A claim you cannot open is not evidence.

Grounding is the whole mechanism, not a disclaimer at the bottom of the page. Retrieval runs against your own indexed documents, and the citation travels with the claim all the way into the work product.

  1. 01

    Retrieval is bounded by your corpus

    An answer is composed from passages retrieved out of your own indexed documents — filings, agreements, transcripts, policies, case records. The agent is not asked to recall a fact; it is asked to find the passage that carries it.

  2. 02

    Each claim carries a citation

    Every generated statement is emitted with the source passage behind it and a locator for that passage: the document, the version, the section or page. A claim with no supporting passage is not presented as a finding.

  3. 03

    The reader can open the passage

    A citation is not a footnote for decoration. From the claim in the memo, the brief or the case narrative, a reviewer opens the passage itself, in the source document, and reads the surrounding text.

  4. 04

    Unsupported gaps are named, not filled

    Where the documents do not answer the question, the draft says so and names what is missing, rather than producing a plausible figure that no reviewer can trace.

Entitlements

Your access model, applied to the answer.

Retrieval is filtered by the permissions your source systems already hold, at the moment the question is asked. Agents are subject to the same machinery, under identities of their own.

Inherited, not re-declared
Permissions come from the systems that already hold your documents. Versidon does not ask you to rebuild an access model beside the one you maintain, and does not become a second place where access drifts.
Enforced at query time
Entitlements are applied when the question is asked, against the permissions in force at that moment — not at index time and then cached. A document a person cannot open cannot reach that person's answer, and revocation takes effect on the next query.
Agents hold their own identity
An agent runs under its own least-privilege identity with an explicit scope, and is entitled to less than the people it works for. It never runs as a person, and never inherits a person's approval rights.
Scope is visible on the work
The work product records which identity produced it and what it was allowed to read, so a reviewer can see the boundary the draft was written inside.

Segregation of duties

The platform stops where the decision begins.

Initiator, reviewer and authoriser stay three distinct roles, and an agent occupies only the first of them. For anything irreversible, Versidon prepares the pack, states what it could not support and names the residual risk — then waits.

  1. 01

    Initiator

    The work is prepared — the memo drafted, the covenant tested, the case narrative written, the exception assembled — with sources attached and agent-written blocks marked.

  2. 02

    Reviewer

    A person reads against the evidence and accepts, amends or rejects. Until acceptance, agent-written content stays marked, attributed and reversible.

  3. 03

    Authoriser

    Anything irreversible — releasing a payment, filing a report, approving a facility, sending externally — waits for the holder of that entitlement. The platform names the residual risk and stops.

No configuration lets an agent hold the entitlement for an irreversible action.

Model risk management

Registered, validated, evaluated, reversible.

Model risk teams ask for an inventory, an owner, a validation status, a review date and evidence that a change was tested before it shipped. Versidon keeps those in the platform rather than in a spreadsheet beside it.

Model registry
Every model approved for regulated use is registered with its validation status, its owner and its next review date. A model that is not approved cannot be called, and an expired review is visible before it becomes a finding.
Agent registry
Each agent is registered with its purpose, its scope, its entitlements and the policy sets it works against, so a reviewer can ask what a given agent is permitted to do and get one answer.
Evaluation before publish
Agents are evaluated against labelled cases drawn from your own work. When a suite falls below its threshold, publish is blocked — the gate is enforced by the platform, not left to the builder's judgement.
Versioning and rollback
Agent and prompt versions are retained with their evaluation results. A version that behaves badly in production rolls back in one step, and the rollback is itself an audit event.
Change is on the record
Registration, validation, approval, publish, threshold change and rollback are all logged with actor and timestamp, which is what a model-risk reviewer usually wants to see first.
Control governance screen: model registry with validation status and owner, agent registry, entitlements and the event log
CONTROL — MODEL REGISTRY, AGENT REGISTRY, ENTITLEMENTS AND THE EVENT LOG IN ONE PLACE

Audit

One log, for people and agents alike.

Human and agent actions land in the same immutable log, so an examination does not have to reconcile two histories. Entries are retained and exportable for examination.

ACTOR

The person or the agent identity that acted, never a shared service account.

ENTITY

The document, facility, case, deal or exception the action was taken on.

WORKSPACE

Where the action happened, so the log reads in the same shape as the work.

TIMESTAMP

When it happened, in one clock across human and agent events.

Data handling

Your tenant is the boundary, and it does not move.

Stays in your tenant
Documents and the indexes derived from them remain inside your tenant. Work product, citations and audit records live there with them.
Not used for training
Your data is not used to train models and no customer data crosses into a shared model. This is a property of the architecture, not an opt-out.
Residency by region
Data is held in the region you select, so a local requirement can be met without holding a separate copy of the platform.

SOC 2 TYPE II · ISO 27001 · GDPR · DATA RESIDENCY BY REGION

What your reviewers will ask

The questions, answered plainly.

Where does our data sit, and is it used to train anything?
Documents and the indexes derived from them stay inside your tenant. Your data is not used to train models and does not cross into a shared model. Residency is set by region.
Can a user get an answer built from a document they are not entitled to read?
No. Entitlements are inherited from your source systems and enforced at query time, so an unentitled passage is never retrieved into that user's answer.
Can an agent approve something, or approve its own work?
No. Agents hold their own least-privilege identity and are not granted approval rights. Initiator, reviewer and authoriser remain distinct people, and anything irreversible waits for the entitlement holder.
How do we tell what the agent wrote from what our analyst wrote?
Agent-written blocks are marked and attributed in the document itself, and stay reversible until a person accepts them. The audit log carries both kinds of authorship in the same record.
How do we validate the models before we let them near regulated work?
Through the registry: a model is usable only once it is registered and its validation status permits it, with a named owner and a review date. Unapproved models cannot be called.
What stops a change in an agent from quietly degrading quality?
Evaluation against labelled cases gates publish. Below threshold, the version does not ship; in production, a bad version rolls back in one step and both events are logged.
What can we hand an examiner?
The immutable log — human and agent actions with actor, entity, workspace and timestamp — retained and exportable, together with the cited evidence behind the work product itself.
What does Versidon refuse to do?
Take the decision. The platform prepares the pack, states what it could not support, and names the residual risk. Filing, releasing and approving stay with your people.

Bring your security, audit and model-risk reviewers to the same session.

Request a Demo