Security and data handling
Built for sensitive transformation knowledge.
A transformation model contains a business's most candid internal knowledge. Bontology is built to protect it: controlled access, client-owned isolated data, and a full evidence trail behind every output. Here is exactly how we handle it, stated honestly.
Access control
Access is role-based and least-privilege. Each person sees only what their role needs, and nothing more.
Executives
See published outputs: the architecture, the ranked problems, the plan, the evidence behind each figure. They decide from what the model shows, not from raw interview material.
Consultants and analysts
Work the model directly: review, reconcile, verify, certify. Their access is scoped to the engagements they are assigned to.
Business users
Are interviewed and can review what they contributed. They do not see other stakeholders' raw answers or unrelated parts of the model.
Data handling and privacy
Interview responses and the model built from them are stored to serve the engagement they came from, not repurposed, not pooled, and not used to train a shared or general-purpose model. Business users are told plainly what an interview is for before they answer.
Fig. 1 · provenance as a security control
Evidence and provenance
Every model object carries a verification state and a link back to the interview line it came from. That trail is not a reporting feature bolted on afterward: it is how you can tell what a system did, when, and on what basis.
An audit trail records who changed what, and when, at every state transition.
Human review
AI classification is never the last word. Low-confidence items route to an exception queue for a person to adjudicate before anything is certified. Nothing Bontology surfaces as a decision-ready output has skipped human review.
Fig. 2 · the isolation guarantee
The isolation guarantee
Your model is client-owned and isolated per engagement. It is never commingled with another client's data, never exposed to anyone outside your engagement, and never used to benchmark you against other clients.
Security posture and roadmap
Bontology is an early-stage product, and we would rather tell you that plainly than imply more than is true.
What is in place today
Role-based access, human review of every AI classification before certification, and a full audit trail with source provenance on every model object.
What is not yet in place
We do not hold SOC 2 or ISO certifications. Formal third-party certification is on our roadmap as the company grows; until then, this page is the accurate statement of our posture.
Contact
Questions about how we handle your data, or a security concern to report.
See how the model treats evidence and access, on a business like yours.
A short conversation, then a guided assessment. Your model stays yours.