Trust & governance

It runs inside your workspace, on your permissions.

The alternative your staff are already using is a personal chatbot with your documents pasted into it — useful for one person, invisible and unowned for the organisation. Wocul's proposition is the same capability inside your boundary, with a permission model, an audit trail and an owner.

Boundary

Inside your organisation

Your documents, your connector credentials and everything Wocul AI produces stay within your own workspace. Nothing is pooled with other customers, and nothing your team asks becomes training data.

Permissions

It sees what the asker may see

Every project carries owner, member and viewer roles, and an investigation is scoped to the access of whoever asked. There is no privileged account with a wider view of the organisation than its people have.

Read-only

Nothing is written back

A connected system is checked for read-only access before the link is accepted. Every query is inspected and capped before it runs, execution time is bounded, and each call is logged. Writing to your systems is not merely disallowed — it is unreachable.

Audit

Every read on the record

Each investigation keeps its own steps, and every look into a connected system is logged with who, when and what. What was read to reach an answer is as inspectable as the answer.

Input safety

Documents cannot give orders

Text reaching Wocul AI from a document or a pasted question is treated as material to read, never as instructions to follow, so a booby-trapped file cannot redirect an investigation.

Cost

Metered and capped

Investigations are counted against a monthly allowance you can see, so AI spend is a line on a plan rather than an open tap.

Connectors

Writes are structurally unreachable.

A connector is not a promise not to write. It is an access path that cannot.

  • Read-only access is verified before a link is accepted — a credential with write permissions is refused.
  • Every query is parsed and rejected unless it is a single read.
  • A row cap is injected into the statement itself, not applied afterwards.
  • Execution time is bounded server-side, so a runaway query is killed.
  • Credentials never leave the platform: the AI service asks the platform to make the call and never sees a token.
  • Every call writes an audit row.

What reviewers ask

Where does our data live?
In your organisation’s own workspace, isolated from other customers. Documents you upload stay yours; you can remove them, and removal takes the derived index with it.
Is our data used to train models?
No. Nothing your team uploads, asks or receives is used to train anything, for us or for anyone else.
Who can see an investigation?
The people who can already see the project it belongs to. An investigation cannot widen access — it is scoped to the requester and inherits the project’s roles.
Can we get a subprocessor list?
Yes — the current list is provided under the data-processing agreement, along with the regions your data is stored and processed in. Ask and we will send both before you commit to anything.
What happens if we leave?
Your documents and the reports produced from them are exportable, and the workspace can be deleted on request. Reports already export to PDF and Excel at any time.

Bring your security questionnaire.

We would rather answer it against a real pilot than in the abstract — one team, one document set, one connected system.