Security and trust

Customer evidence stays protected, governed and traceable.

BAI Analytics protects customer data from source connection through analysis and reporting, with enterprise access controls, regional infrastructure and evidence-level traceability.

Security documentation and restricted reports are available through our Trust Center.
BAI Analytics · Theme evidenceSource-linked analysis
Theme analysis

Unprofessional staff conduct

Verified theme
Priority 0.4862 responsesVery negative
Summary

Customers describe staff as dismissive or unhelpful when asked for assistance, especially when accessibility support is required.

Supporting evidence Every finding opens to its source
Dismissive when asked questions · 22Accessibility needs · 4Confrontational behavior · 7
Original responseNegative

“I asked for help using the accessibility ramp. The response was abrupt.”

Source record · Jul 2 · Access governed by role
Original responsePositive exception

“The station employee took the time to explain the accessible route.”

Source record · Jul 4 · Access governed by role
AICPA SOC for Service Organizations
SOC 2Independently assessed security controls
GDPR
GDPREuropean data protection controls
EU
Regional hostingEU and North America environments
ID
Controlled accessSSO, MFA and role-based permissions
01
Private AI processingCustomer data is never used for model training

Security follows the evidence

Protection at every stage of the customer data journey.

Security is not a badge added after analysis. It governs how data enters BAI Analytics, where it is processed, who can use it and how every conclusion can be defended.

Customer data journey

Secure ingestion

Bring in only the evidence you authorize.

Connections are authenticated, governed and scoped to the systems and data required for analysis.

Authorized source record
Zendesk
Service conversationTicket #58121 · Location 114
“The estimate changed twice after I added a second service.”
Authenticated source connectionScoped import configurationGoverned API accessSource metadata retained
European UnionSelected
StorageEU region
ProcessingEU region
EncryptionAES-256
TransitTLS 1.2+
North AmericaAvailable
StorageNA region
ProcessingNA region
EncryptionAES-256
TransitTLS 1.2+
Authorized evidenceCustomer recordsOnly the data required for the analysis.
Private AI environmentRegional Vertex AICustomer inputs and outputs are excluded from model training.
Governed outputTheme and evidenceAnalysis remains connected to its sources.
Workspace permissions
ExecutiveReports
AnalystEvidence access
Regional leadAssigned locations
Authorized conclusion

Weekend multi-service visits are driving longer waits in 12 locations.

Supporting records486
Evidence accessRole governed
01
Active workspaceCustomer-directed retention policy applies
02
Portable evidenceAuthorized data can be exported
03
Verified deletionDeletion follows contractual requirements
Retention controlsPolicies align with customer and legal requirements.
Export supportEvidence remains portable for authorized users.
Deletion workflowCustomer content can be removed when required.

Private by design

Your customer data remains your customer data.

BAI Analytics processes customer evidence only to provide the service. It is not used to train, fine-tune or improve our models or any third-party model.

01
No customer-data model trainingInputs, documents, prompts and generated outputs are excluded from model training.
02
Private cloud AI environmentAI inference runs within a private Google Cloud Vertex AI environment, not a public consumer API.
03
Contracted subprocessorsSubprocessors are governed by data processing agreements and documented for customer review.
04
Customer-directed retentionCustomer content can be exported and deleted according to contractual and legal requirements.

Data residency

Choose where customer evidence is processed.

Separate regional environments support data sovereignty requirements without separating teams from a consistent BAI Analytics experience.

One BAI Analytics experienceCustomer evidence is routed to the contracted regional environment
EU
Environment isolated

European Union

Customer evidence remains inside the selected EU environment throughout storage, processing and AI inference.

Customer storageEU region
BAI processingEU region
Private AIEU inference
AccessCustomer roles
NA
Environment isolated

North America

Customer evidence remains inside the selected North American environment throughout storage, processing and AI inference.

Customer storageNA region
BAI processingNA region
Private AINA inference
AccessCustomer roles
Customer content stays inside the contracted regional boundary.No environment crossover

The appropriate environment and transfer requirements are confirmed during procurement and contracting.

Identity and access

The right evidence for the right people.

Enterprise identity controls and granular permissions help organizations give each team the access it needs without opening the entire evidence base.

Standards-based SSOConnect enterprise identity through SAML 2.0 or OpenID Connect.
MFA and least privilegeProtect accounts and administrative access with layered identity controls.
Role-based permissionsGovern analysis, reporting and source evidence by organizational responsibility.
Workspace access SSO enforced
Role
View
Analyze
Manage
ExecutiveEnterprise reporting
×
AnalystEvidence and themes
×
Regional leadAssigned locations
×
×
AdministratorWorkspace governance
Identity provider connectedAccess governed

Evidence-level traceability

From source to decision, the evidence stays attached.

BAI Analytics preserves the source record and relevant metadata behind each finding, giving teams a defensible path from an executive conclusion back to the customer evidence.

See how the platform works
Executive conclusionWeekend multi-service visits are driving longer waits in 12 locations.
Survey184 responses
Service237 conversations
Operations65 visit records
486 supporting records available for review

Security operations

Controls that keep working after launch.

Operational safeguards are continuously maintained, reviewed and documented. Technical and procurement teams can inspect the relevant evidence in our Trust Center.

Control area
How it is applied
Evidence
Data protection
TLS 1.2+ in transit, AES-256 at rest and regional cloud environments.
Trust Center
Secure development
Code review, controlled deployment, dependency monitoring and documented remediation.
Control records
Monitoring and response
Continuous Vanta monitoring, incident procedures and customer communication processes.
Monitored
Business continuity
Cloud resilience, backups and reviewed recovery procedures.
Diligence
Vendor and personnel
Subprocessor review, least-privilege employee access and security training.
Documented