AI Safety Framework

Built safe by design

EnviroAutomate's AI Assistant is a conversational assistant embedded directly in the platform. It helps environmental consultants find information, navigate the application, and draft content, all within the secure EnviroAutomate environment.

The short version

Your data is:

  • Isolated to your organisation
  • Never used to train AI models
  • Processed only in Australia
  • Protected by high-sensitivity content guardrails
  • The AI cannot change your data without a human clicking Approve
  • Every interaction is logged

Your data is fully protected

No Model Training on Your Data

EnviroAutomate does not use customer data to train AI models. Your questions, site data, and report content are never added to a training dataset. This is guaranteed by our AI model provider, not just a policy we set.

Your Data Stays in Australia

All AI processing happens in Australian AWS regions (Sydney ap-southeast-2 and Melbourne ap-southeast-4), via AWS’s Australia cross-region inference profiles. Your data never leaves Australia.

Strict Tenant Isolation

The AI Assistant can only see your organisation’s data. There is no mechanism for another client’s AI session to access your projects, sites, or analytical results.

What the AI cannot do without your approval

The AI Assistant cannot change anything in your data on its own. Any action that creates, updates, or assigns work appears as a proposal with an approval card showing exactly what will be changed and to which record. Nothing is written until a person clicks Approve.

The assistant can read freely

  • Look up sites, projects, fieldwork tasks, client reports, and action items.
  • Query analytical results, exceedances, trends, and investigation levels.
  • Look up laboratories, analytes, and guidelines.
  • Summarise data already in EnviroAutomate.
APPROVAL REQUIRED

Writes require approval

  • Navigating you to a page in the application.
  • Creating an action item.
  • Dispatching, reassigning, or completing a fieldwork task.
  • Adding a note to a site, project, or report.

If you take no action on a proposal, nothing happens. Only the user who proposed the action (or a tenant admin) can approve or reject it.

Safety features

Human approval is required on every write

The AI cannot change your data without an explicit click. Every write action runs through a propose-approve-execute workflow. Authorisation is re-checked per action: your tenant and role are re-checked at the moment each AI action runs, not just at the start of the chat. Approved actions are written together with their audit entry in a single database transaction.

Content guardrails apply on every request

Guardrails block harmful, off-topic, and inappropriate content at high sensitivity. Prompt injection defences detect and block attempts to manipulate the AI through malicious input before they reach the model. Data injection defences stop malicious content embedded in your data (crafted notes, filenames, and similar) from breaking out of the assistant’s display, query, or formatting layers.

Topic restriction keeps the AI focused

The assistant is restricted to environmental consulting subject matter; it cannot be used as a general-purpose chatbot. When content is blocked, users see a safe generic message and no sensitive details are exposed.

MFA and encryption throughout

Every user must pass multi-factor authentication before accessing AI features, no exceptions. TLS 1.2+ in transit with HSTS enforced; AES-256 at rest for all AI messages and outputs stored in the database.

Full audit trail

Every AI conversation, tool call, and action is stored in the EnviroAutomate database:

  • The user identity is recorded on every message.
  • Full conversation history is retained.
  • Every tool call is logged with its inputs, the user it was acting for, and whether it succeeded or failed.
  • Every proposed action is recorded with its lifecycle: proposed, approved, rejected, executed, or failed.
  • The user who clicked Approve or Reject is recorded against the action.
  • Timestamps cover every interaction.

Want the deeper detail? Read the full AI posture for data residency, guardrails, and audit detail, or review our technology and hosting posture for architecture, HA/DR, and SLA.

Ready to transform your environmental reporting?