Trust Centre

Buyer confidence, in one place.

Everything an owner, board or IT adviser needs to know before working with us: how we use AI, where data lives, who can see it, and who stays in control.

Human-approved consequential actionsNo client data in public AI toolsTenant-isolated by design

How we use AI

AI prepares, recommends, coordinates and executes bounded low-risk actions inside the records where work happens. Accountable people retain every consequential decision.

AI transparency

Where your data lives

Client data is stored in access-controlled, tenant-scoped systems hosted in Australia-eligible regions. It is never placed in public consumer AI tools, and never used to train third-party models.

Privacy notice

How we secure it

Tenant isolation enforced at the database layer, least-privilege roles, audit trails on every record, encrypted storage and independent production review before each go-live.

Security

Human controls

Client communications, commercial terms, publication and production changes all require explicit human approval. Every AI run is logged with actor, model, inputs and outputs.

Human gates and red lines

Subprocessor categories

Who touches the data, and why.

  • Application hosting and database

    Runs the platform, portal and CRM with row-level tenant isolation.

  • AI model gateway

    Processes governed prompts for drafting, summarising and qualification. No training on client data.

  • Email delivery

    Sends invitations, notifications and replies you have asked for.

  • Error monitoring and analytics

    Keeps the platform reliable. Analytics is collected with consent and aggregated.

A named subprocessor list is provided to clients on request and before contract.

Assurance approach

Checked before go-live, watched after.

  • Permission and data-isolation tests run before every release.
  • Recovery and rollback rehearsed, with a manual continuity path documented.
  • Incident owner named; post-incident review shared with affected clients.
  • AI runs kept in a register so behaviour can be audited and evaluated.
  • Client proof published only with written consent and a stated evidence status.

Questions, requests or concerns

Talk to a person.

Privacy requests, security questionnaires, incident reports or a copy of our subprocessor list — email hello@studioambira.ai and the founder will respond within one business day.

Stay in the loop

Occasional notes on building AI-native businesses — practical, no noise. Unsubscribe any time.