TomPilot
Security & compliance

Ai you can put in front of a board.

TomPilot was built governance-first, not bolted on afterwards. The data architecture is designed against GDPR, ISO 27001 and ISO 42001, and written up for external DPO review.

REGULATION
GDPR

Full data-subject rights, self-service export & erasure.

STANDARD
ISO 27001

Information security management, isolation & audit.

STANDARD
ISO 42001

Ai management, consent, cost & prompt governance.

RESIDENCY
UK · London

Data in eu-west-2, encrypted, seven-year retention.

Architecture designed to these standards. Formal certification is in progress; documentation available under NDA.

Isolation by design

Your data never shares a process with anyone else's.

Every table carries row-level security scoped to your workspace, with a second tier of isolation between users inside it. Each workspace gets its own Slack token, its own Anthropic key and its own agent process, so credentials and conversations are never pooled.

Row-level security on every table, verified by a dedicated isolation test suite.
Per-workspace key & process, no shared LLM key across tenants.
Secrets held in a vault, fetched at runtime, never in plain config.
TENANT ISOLATION
Workspace A
RLS scope · own key
own agent process
own Slack token
Workspace B
RLS scope · own key
own agent process
own Slack token
Postgres · Row-Level Security
London · eu-west-2 · encrypted at rest
GDPR in practice

Data-subject rights that actually work, not a policy PDF.

Access
Subject access & export

Self-service download of everything held about a person, generated on demand as JSON or CSV over a registry of every PII field.

Erasure
Three modes of deletion

Full erasure across every linked record, soft-delete with restore, or a consent-gated ownership transfer. Customer-initiated and operator-run.

Consent
Article 7(3) revocation

Withdraw Ai consent per user and it's enforced before any model is called, so a refused user incurs no processing and no cost.

Immutable audit log

Append-only, trigger-enforced, 30+ action types across both runtimes. Admins can view it in-app.

2FA & auth hardening

TOTP with backup codes, tenant-scoped enforcement, sudo mode, login rate limiting, 16-char passwords.

Retention enforcement

A documented retention schedule with daily enforcers for seven-year and two-year classes, plus heartbeat alerting.

Role-based access

Operator, admin and member roles, with time-boxed, revocable operator debug grants.

Ai cost & prompt audit

Every model call is budget-capped, costed and version-hashed with a full audit trail, the ISO 42001 spine.

Encryption & residency

Encrypted at rest and in transit, hosted in London, passwords hashed with bcrypt, never readable by us.

Doing a security review?

We'll send the security pack, the GDPR architecture write-up and a DPA. Real answers from the people who built it.