Company Brain Data Safety: Who Can See What, and How to Control It
Putting your company's knowledge in one place raises a fair question: who can see it? Here are the questions to ask about access control, data separation, human approval and deletion — before you load a single document.
By Garvit Jain, Vardhan AI
A Company Brain holds your prices, your policies and possibly your customers' details, so the first question isn't "what can it do?" — it's "who can see what?" A good setup answers that before any document goes in. These are the questions to ask any vendor, including us.
1. Is access scoped by role?
A support agent shouldn't see payroll; a new intern shouldn't see investor documents. The Brain should only surface what a given person or AI role is permitted to see, not everything it knows. Ask how permissions are defined and who can change them. At Vardhan AI, each AI role is scoped to the systems and data that role needs, not a general-purpose key — see our security and governance page.
2. Is your data separated from other companies'?
Your knowledge should never be mixed with another client's, sold or shared. Ask directly. Our position: what we build for you stays specific to your business and isn't shared with other clients or sold.
3. Is there a human in the loop for high-stakes actions?
Reading knowledge is low-risk; taking action isn't. Anything with real consequence — a large refund, a message to a key customer, a payment — should require a person's approval, and stay that way until the action has earned trust. Check that approval is a real step, not a setting buried somewhere.
4. Is there a record of what happened?
You should be able to see what was asked, what the Brain answered, which sources it used, and what it did. An audit trail is how you catch mistakes and how you prove control later.
5. What happens to your data if you leave?
Ask before you sign: can you export it, and can you have it deleted? This is scoped per engagement with us, so we agree it up front rather than assume it.
6. What is the vendor honest about?
Be wary of a vague "enterprise-grade security" line. We're a small team and we don't hold formal third-party certifications such as SOC 2 or ISO 27001 today; we'd rather say so than imply a compliance level we haven't earned. If a specific certification is a requirement for you, tell us early.
What you can do on your side
- Decide up front which folders and documents are in scope — leave sensitive HR and finance material out at first
- Name an owner for access decisions
- Start with one department and expand once the rules feel right
- Review the audit trail in the first weeks
For the sequence we recommend, see how to set up a Company Brain. Have a specific requirement? Email contact@vardhanai.com or Talk to us →.