Trust & security

The questions a serious buyer should ask.

Three products, three different trust trade-offs. Here is who owns what, where your data lives, which models run, and what happens when the stakes are high.

Our products

SaaS for consultancies

Yojivo

An all-in-one operations platform that brings the tools a consultancy runs day-to-day (CRM, finance, ERP-style workflows, hiring and AI interviews) into one place. Runs on public LLMs by default, with the option to bring your own model.

Sovereign enterprise AI

ThirdEye

A single-tenant application in your cloud (VPC), with cited answers and an agreed audit design. Managed inference processes selected data outside that VPC. Self-hosted and disconnected inference are distinct options requiring validation.

AI voice agent for SMBs

Ahoy

An AI receptionist that answers inbound calls 24/7 with Australian phone numbers, books appointments, and sends post-call summaries to your team.

How a deployment sits in your cloud.

APPLICATION VPC: PROPOSED CONTROLSYOUR SOURCESDocuments and drivesData roomsLedgers and KPI reportsPolicy registersindexedYOUR SYSTEMSTicketing, service deskCRM and ERPWorkflow toolsthe record changes hereactsTHIRDEYE, SINGLE TENANTAnswers, with citationsAnalyses and draftsActs through governed toolsapproval requiredWatches and escalateson your scheduleAudit scope to verifycitations to reviewtest team isolationverify roles and accessPRIVATE ENDPOINTConnectivity onlynot model hostingpromptsMANAGED INFERENCEOutside app VPCRegion / retention:verify with providerYOUR KEYSCustomer-managedencryptsprodtestdevSTAGED ENVIRONMENTSYOUR PEOPLEask, approve, review the logSSO and rolesblock unapproved destinationsUnapproved APIsUnapproved servicesdeny and verifyAKIMADesigns, deploys,operates with youvia governed accessoperated via your access
Illustrative managed-inference option, not a deployed-control attestation. The application VPC contains the private endpoint, not the managed model. Prompts and retrieved excerpts cross into the approved model service; verify its region, retention and processor terms. Self-hosted and disconnected designs require separate review.Scroll sideways for the whole picture.

The document your reviewer will ask for.

A security and architecture overview covers deployment, data handling, models, identity and isolation, actions and approvals, governance and audit, operations, and our compliance posture. Available on request, under NDA where your process requires it.

What it covers

  1. Purpose and scope
  2. Deployment model
  3. Data handling
  4. Models
  5. Identity, access and isolation
  6. Actions and approvals
  7. Governance and audit
  8. Operations and support
  9. Compliance posture

The eight questions procurement always asks.

  1. 01

    All products

    Who owns the code and the data?

    You own your data and can take it with you, exportable on request at any time. Yojivo and ThirdEye engagements run month-to-month with no lock-in; Ahoy has a 3-month minimum term, then monthly. Akima retains the platform IP behind Yojivo, ThirdEye and Ahoy; your data, configuration and decisions never become ours.

  2. 02

    Yojivo and ThirdEye

    What AI models run under the hood?

    It depends on the product, by design. Yojivo runs on public LLMs by default, with the option to bring your own model where stricter data handling is required. For ThirdEye, private connectivity to managed inference does not place the model inside your VPC. Agree service region, retention and processor terms. Self-hosted VPC inference runs on customer-controlled compute; genuinely disconnected operation additionally needs local models and no external runtime dependencies.

  3. 03

    ThirdEye

    What happens if the AI gets something wrong?

    Require source citations and reviewer checks; a citation is not proof that an answer is correct. Start read-only, test unsupported-answer behaviour and permission boundaries, and require a person to approve any consequential action. Validate the audit record and approval path before enabling writes.

  4. 04

    Yojivo and ThirdEye

    Where does our data live, and how is it isolated?

    Yojivo is hosted in the Australian region today, and we can stand up an instance in any region you require, such as the EU. For ThirdEye, agree the application region separately from inference, indexing, backups, telemetry and support-access locations. Approve destinations, key coverage and team/source permission tests before access. These are deployment requirements, not universal verified controls.

  5. 05

    ThirdEye

    Will it pass our security review?

    Security approval belongs to your reviewers. Scope separate dev, test and production environments, data-flow evidence and access tests within your procurement and cloud-governance processes. A pilot still needs its own approval; this page is not an attestation.

  6. 06

    All products

    What is your security and compliance posture today?

    We align to the Australian Privacy Act 1988 and design to enterprise control expectations: an agreed key-management and egress design for ThirdEye, with audit and role-based access requirements to verify in each environment. We are progressing a formal certification roadmap, and where a specific certification is required for your procurement, we scope it with you rather than claim it prematurely. A security and architecture overview is available on request.

  7. 07

    Enterprise and Ahoy

    What are your SLAs and support response times?

    Enterprise service levels for ThirdEye and enterprise Yojivo rollouts are set per engagement and written into your agreement. Support is direct and founder-led. Ahoy answers calls 24/7 automatically by design, with post-call summaries sent to your team.

  8. 08

    On request

    Can you provide client references?

    We are currently deploying ThirdEye with an enterprise client that operates across multiple countries: in their own cloud, in their region, through full enterprise security review. Further client references are available on request under NDA.

Still have a question we should answer here?

Book a briefing and ask us directly about deployment, data handling, security review, or anything else a procurement team needs to see.