How your data is kept
Every tenant's data is isolated in the database itself, no model can write a business record without a person approving it, and every model call is recorded with its cost, confidence and injection flags.
Tenant isolation
Isolation is a database property here, not an application convention. Each operational table carries an organization id and a row-level security policy; the application connects as a least-privilege role whose grants are pinned to a reviewed manifest, and each transaction sets the tenant claim inside the transaction itself.
Every tenant table is checked in continuous integration to carry an isolation policy and a runtime-role grant, so a table cannot ship without them. Two things are staged and not yet the default: fail-closed behaviour when a request arrives with no tenant claim, and a two-organisation runtime harness that exercises the policies against a live database.
What the AI is allowed to do
- Propose, never write
- Extraction, matching and sourcing produce proposals. A person approves, corrects or rejects before anything becomes a record or leaves the building.
- Grounded fields only
- Every extracted field carries an evidence span from the source document. Ungrounded fields are dropped and counted.
- Rules before models
- Catalog matching runs deterministic rules first; the model only re-ranks what rules could not place, and abstains below the tenant's threshold.
- Tool tiers
- Untrusted text is handled by tool-less calls. Tools are available only to calls whose input is trusted, enforced in the type system.
- Budgets
- Per-tenant spend has hard stops. A runaway job halts instead of billing.
The ledger
Every model call writes a row: prompt hash, model, tokens, cost, confidence, injection flags, tenant and purpose. You can see what the AI did on your data, what it cost, and how sure it was — per call, not as a monthly total.
Secrets and access
Integration credentials are held in environment configuration today, never logged and never exported. Per-tenant envelope encryption — a key per secret, decrypted only inside a tenant-scoped operation — is designed and is the next migration. Support access is bounded, and the audit trail a tenant can read for itself is being added.
What is not true yet
We are pre-launch and say what is missing: no SOC 2 report, no penetration-test letter to share, single-region hosting, and a support model that is a person rather than a rota. On the list above: fail-closed tenancy and the two-organisation isolation harness are staged but not yet the default; per-tenant envelope encryption of secrets is the next migration; the evaluation set exists but does not yet gate releases; and the support audit trail is not yet visible to tenants. If any of those is a blocker for your pilot, tell us at the first call rather than after.
Questions that need a real answer, not a page: write to hello@bizily.ai.
Questions
- Are you SOC 2 certified?
- No. The system is designed against SOC 2 criteria and the controls are mapped to them, but there has been no audit and we do not claim a report. We will say so plainly when that changes.
- Is my data used to train models?
- No. Tenant content is not used to train models, ours or a provider's. Model calls run through a gateway configured for zero data retention where the provider supports it.
- Can another tenant see my prices or customers?
- No. Every operational table carries an organization id with a row-level security policy, and the runtime database role is least-privilege. Fail-closed behaviour when a request carries no tenant claim is staged and becomes the default before any outside tenant is onboarded.
- What happens if a request contains a prompt injection?
- Untrusted text is only ever passed to tool-less, structured-output calls, wrapped in a per-call random delimiter with a canary. A canary echo or delimiter breakout flags the document, forces human review and shows a banner. Injection cases are part of the release benchmark.
- Who at Bizily can see my tenant?
- Support access is time-bounded and granted per request, and we do not browse tenants. A per-read audit trail you can inspect yourself is being added.
- Where does the data live?
- Postgres on Neon, application hosting on Vercel, model calls through the Vercel AI Gateway, and Resend for the e-mail this site sends. Those four are the whole list today. Tell us if a region is a requirement for your pilot.
- Can I export or delete everything?
- Yes. Export is per tenant and includes the ledger; deletion removes tenant rows and secrets on request. Retention windows are set per tenant, and legal holds are explicit.