Security, privacy and governance

Control, privacy and accountability for enterprise AI operations.

Ultma is designed so organisations can define where data may go, what each Agent may access, which actions require approval and how every execution is reviewed.

Data boundaries

Define sources, destinations, approved models and retention rules for each workflow.

Least-privilege access

Give each Agent only the systems, tools and data needed for its assigned role.

Human approval

Require review before high-impact, irreversible or sensitive actions are completed.

Audit and traceability

Review workflow version, model and tool activity, approvals, outcomes and exceptions by verified scope.

Provider transparency

Document which external providers may process data and where relevant processing may occur.

Evaluation and change control

Test intended behaviour and operational quality before deployment and after material changes.

Evidence-first trust pack

Enterprise assurance should be inspectable.

Security statements should match the product, deployment architecture, customer contract and available evidence.

Security & Data Handling Overview

Control scope, architecture choices and ownership.

Architecture and data-flow diagram

Inputs, stores, model calls, connectors, logs and processing countries.

DPA and provider disclosure

Role allocation, subprocessors, model providers and processing locations.

Evaluation and deployment evidence

Risk assessment, test summary, authorisation and operating runbook.

Evidence before claims

No certification or residency claim should run ahead of proof.

Australian data residency, zero retention, no-training, SOC 2, ISO 27001, Essential Eight compliance and uptime claims are not made on this preview. Publish only verified scope and precise contractual wording.