Enterprise
AI agents with the controland the SLAs you need.
Integration with your systems, data isolation enforced by the database, dedicated support and written guarantees. The technical detail your security team will ask for, already published.
Guarantees and SLAs
What we deliver today and what we sign.
Anything dated goes into the contract with its date, and with the right to terminate without penalty if it is not met.
- Today
DPA signed before any data flows
- Today
RLS isolation with blocking tests
Enforced by the database, not by trust in the code
- Today
Human handoff always available
- Today
The agent identifies itself as AI from the first message
- Today
Every version approved before promotion, with audited rollback
- Q4 2026
Verifiable deletion (GDPR art. 17)
- Q4 2026
99.5% SLA with credits
- Q4 2026
50–60% resolution guarantee
With a verified definition of resolution, not containment
- Q4 2026
Dedicated queue per tier
- Q4 2026
Monthly report with operating data
- Dated
SOC 2
On the certification roadmap; security questionnaire and controls under NDA
- Dated
SSO
Under evaluation; the date is set in the architecture review
Security and control · nine isolation controls
Isolation enforced by the database.
- 01
Isolation enforced by the database
RLS with SET LOCAL ROLE per transaction: the code cannot pick the tenant even if it tried.
- 02
Tool whitelist at two points
Explicit list per agent, checked at two points of the runtime. What is not listed does not run.
- 03
Audit with the real actor under impersonation
When an operator acts “as” a tenant, the log records who they really were.
- 04
Runtime isolation monitoring
A watcher turns violations into alerts with an owner, not logs nobody reads.
- 05
No CORS by design
The API exposes no surface for browser requests from arbitrary origins.
- 06
HMAC webhooks, fail closed
Every signed input is verified; if it fails, it is rejected.
- 07
Fail-closed deployment
If the isolation tests fail, the deployment does not ship. It is a pipeline gate.
- 08
Idempotency at two levels
Webhook and queue retries never duplicate effects: deduplication on input and execution.
- 09
No batching across clients
Model calls never mix context from different clients.
How it is measured. Every relevant conversation goes through an automatic judge with per-vertical rubrics: did it resolve? should it have escalated? did it escalate in time? Failures feed the month's improvement cycle.
Tailored deployment
Bounded pilot. Scale in phases.
For the first 3–5 accounts we deploy exactly what exists; everything else goes into the contract with a date and the right to terminate.
- Bounded pilot with scope and price fixed in writing
- Phased guarantees with contractual dates and a no-penalty termination right
- Direct priority on the roadmap for what your security team asks for
- Written commitment to a public case study with metrics once the pilot delivers
Price. Depends on volume, channels, integrations and guarantees. It comes out of the architecture review with a written breakdown.
- Step 1
Architecture review
30 minutes with the engineer who runs the platform. You leave with an honest go/no-go and, if go, the draft blueprint.
- Step 2
Security and DPA
Questionnaire answered, DPA signed, responsibilities split in writing. No real data touches the system before that.
- Step 3
Configuration and evals
Integrations, vertical skills, your own rubrics. Every version requires your explicit approval.
- Step 4
Bounded production, then scale
Go-live on one segment, measurement against the blueprint and phased expansion with exit criteria.
Get security on the first call.
30 minutes with the engineer who runs the platform, not a salesperson. Architecture, integration with your systems, compliance and an honest go/no-go.
Diagnostic · 30 min
Europe/Madrid · 30 min
- Free · no commitment
- With the engineer who runs the platform
- You leave with a clear yes or no, and the scope in writing
