Skip to content
Digicane SystemsDigicane Systems

Trust

Security & Compliance

Digicane Systems treats security, privacy, and compliance as foundational. We maintain an Information Security Management System aligned with ISO 27001 and design AI deployments with access control, audit logging, and data localization options.

  • ISO 27001-aligned ISMS practices for confidentiality, integrity, and availability
  • Role-based access and comprehensive audit logging for AI workflows
  • Data localization strategies including India-based hosting where required

AI controls

Beyond classic ISMS — how Digicane designs controllable enterprise AI.

  • Grounding & citations

    RAG answers prefer indexed enterprise sources with citation lines so staff can verify claims.

  • Human override

    Sensitive tool calls (ERP writes, case opens, hot-lists) can pause for Approve/Reject before acting.

  • Prompt & tool policy

    Agents operate with constrained tool trays and audit IDs — not open-ended shell access.

  • Retention

    Prompt, document, and log retention are scoped per engagement; we avoid indefinite training on your data by default.

  • India residency

    Hosting and retrieval can stay aligned with India localization requirements when contracts require it.

  • Evaluation

    Pilots include evaluation sets for groundedness, refusal behavior, and override coverage before scale-up.

  • Subprocessors

    Model/API and hosting vendors are disclosed in statements of work; you can require an approved vendor list.

Frequently asked questions

Does Digicane train foundation models on our data?+

By default, no. We design retrieval and logging so your documents are used to answer — not to retrain public foundation models — unless a separate agreement says otherwise.

How do you reduce hallucinations on company facts?+

We use RAG with citations, constrain tools, and escalate when retrieval confidence is low.

Can regulated actions run without a human?+

They can be configured that way, but Digicane defaults sensitive steps to human override until you explicitly widen automation.

Where can prompts and transcripts be stored?+

Storage location follows your residency and retention choices — including India-based options.

Do you support DPA language?+

Yes — commercial paperwork can include data processing terms aligned with your counsel’s requirements.

How are AI incidents reviewed?+

Audit logs, eval failures, and override rejects feed into change control and runbook updates.