Data boundaries
Define sources, destinations, approved models and retention rules for each workflow.
Security, privacy and governance
Ultma is designed so organisations can define where data may go, what each Agent may access, which actions require approval and how every execution is reviewed.
Define sources, destinations, approved models and retention rules for each workflow.
Give each Agent only the systems, tools and data needed for its assigned role.
Require review before high-impact, irreversible or sensitive actions are completed.
Review workflow version, model and tool activity, approvals, outcomes and exceptions by verified scope.
Document which external providers may process data and where relevant processing may occur.
Test intended behaviour and operational quality before deployment and after material changes.
Evidence-first trust pack
Security statements should match the product, deployment architecture, customer contract and available evidence.
Control scope, architecture choices and ownership.
Inputs, stores, model calls, connectors, logs and processing countries.
Role allocation, subprocessors, model providers and processing locations.
Risk assessment, test summary, authorisation and operating runbook.
Evidence before claims
Australian data residency, zero retention, no-training, SOC 2, ISO 27001, Essential Eight compliance and uptime claims are not made on this preview. Publish only verified scope and precise contractual wording.