Security & data protection

An AI coach your security review can survive

Your people will tell an AI coach things they would never tell their manager. That is the product — and it is the risk. So every answer on this page comes with the way to check it, because a security review is not a vibe.

Confidentiality

Coaching conversations stay private to the individual, with identities protected. Leaders see aggregated trends — never transcripts.

AI Safety

A deterministic safety screen runs before any model sees a message. The crisis takeover is code: zero tokens, and it cannot be persuaded.

Data Security

Encryption in transit and at rest, tenant isolation, and role-based access control — or no egress at all, in the air-gapped deployment.

Compliance

Data handling designed to align with global privacy standards, including a regulated mode built with the EU AI Act's workplace rules in mind.

Where the data goes

Nothing has to leave your network

The same codebase runs against a frontier cloud model or entirely inside your perimeter — Postgres, local vector search, and a local model, with no internet at all.

Cloud model data leaves

Your networkappdatatranscriptsmodelprovider

Every message goes to an external provider. That is a question your review has to answer, and an exception someone has to sign.

Air-gapped nothing leaves

Your network — no egressappdatamodel

The model runs inside the perimeter. There is no provider, no egress, and no exception to sign — the question stops existing.

The questions your reviewers will ask

Answered, with the way to check each one

“Does it profile our employees?”

It does not have to. One setting disables emotion inference and any durable rating of a person — and it is a property of the deployment, not a checkbox in an admin panel. Emotion records are refused at the database, the last gate before the disk. Scoring variables are refused at load, so they are never registered at all: nothing can capture them, and no later content edit can quietly bring them back.

CEREBROZEN_REGULATED_WORKPLACE=true   # no emotion inference. no person-score.

check it — 16 tests prove it. We will run them in front of your DPO.

“What will it do — not what did it do?”

Routing is a state machine, not a mood. Which method a person gets, what must be true before an agent may hand off, when a session is allowed to close — all of it is code. An auditor can read it. Sessions are reproducible.

check it — we walk the live graph with your engineer and run a real session through it, node by node.

“What do you keep, and can we get rid of it?”

Coaching transcripts, the commitments a person made, and the patterns noticed across sessions. Nothing else. In regulated mode: no emotion record and no score. Deletion is a function of the product, not a support ticket.

Emotion inference · worker scoring

The two things a coaching AI should be most careful about

A coaching product hears a person at their most honest. It is therefore in a position to do two things that, in an employment context, are legally and ethically loaded: infer their emotional state, and keep a durable score about them — computed from a conversation they were told was confidential.

Under the EU AI Act, inferring the emotions of a natural person in the workplace is a prohibited practice, and AI used in employment and worker management is high-risk. Many products in this category do both by default, because the analytics they sell back to HR depend on it.

Regulated mode removes the score, not the coaching. The coach still remembers the goal, the commitments, and what a person is working on. It simply does not keep a rating of them.

This describes how the software behaves; it is not legal advice. Your counsel decides what your obligations are. Our job is to make the answer enforceable once they do.

Bring Calm, Focused Performance to Every Desk

CereBroZen gives every employee an always-on AI coach that improves decisions, performance, and engagement in the flow of work.