Zenias
Inquire
Trust
// 06 Ref. TRUST_SYS.v1

How We Handle Data & Security

Plain-language answers for the IT, legal and operational people who need to assess an engagement before it starts.

Zenias is an Australian AI consultancy, not a cybersecurity provider. Security, data privacy, policies and procedures sit inside our AI Governance service and our delivery practice. This page describes the practice. It makes no compliance, certification or encryption claim that has not been verified for your engagement.

Sovereign AU hostingOr your own VPCNo model training

Book a free discovery call
The AI Governance service

Our Integrations

  • OpenAI logoOpenAI
  • Claude logoClaude
  • Gemini logoGemini
  • Microsoft 365 logoMicrosoft 365
  • Copilot logoCopilot
  • Google logoGoogle
  • LinkedIn logoLinkedIn
  • Facebook logoFacebook
  • Instagram logoInstagram
  • TikTok logoTikTok
  • YouTube logoYouTube
  • Slack logoSlack
  • Notion logoNotion
  • HubSpot logoHubSpot
  • Salesforce logoSalesforce
  • Xero logoXero
  • MYOB logoMYOB
  • Asana logoAsana
  • ClickUp logoClickUp
  • Airtable logoAirtable
  • Make logoMake
  • Zapier logoZapier
  • n8n logon8n

// Your Access, Your Data, Your Systems

Each topic says what happens during an engagement, in the order your technical people usually ask.

00

The access path

Ref. TRUST_SYS.v1
01

What we can reach

Ref. TRUST_01.v1
01

Access

We work inside the access you grant, and only that. During the AI Opportunity Map the scope of access is examined with your IT or technical people alongside APIs, MCP access, data flows and integration feasibility, so the boundaries are known before anything is built.

Access needed for a build or a controlled test is agreed in the written scope, and your technical people review access and data handling while the test runs.

02

Credentials

Credentials belong to you. Access is granted by your people and can be revoked by your people at any point in the engagement.

Where a system needs its own credentials to run, they are scoped to what the system does and agreed with your technical people, not borrowed from an individual's account.

02

What happens to your data

Ref. TRUST_03.v1
03

Your data

Your business data stays yours. Systems Zenias builds run on sovereign Australian infrastructure, private servers or your own VPC, and your data is never used to train external AI models.

For MARIA, the managed AI assistant service, your data stays on private infrastructure and is never used to train external models. Your business data remains yours. Most systems we build go into your environment and become yours, intellectual property included. The only things we keep are the building blocks we bring to every project, and your engagement terms say so in writing.

04

Models and vendors

Model and vendor choice is made per engagement, from the task, your constraints and the data involved, and it is written into the scope so your technical people can see which model handles which data.

The Map's outputs include the data, security and governance risks of each opportunity, so a vendor or model that does not fit your constraints is identified before it is chosen.

03

Before it reaches production

Ref. TRUST_05.v1
05

Controlled testing

We prove the recommendation in a controlled environment before anything reaches production. The people who will use the system try it on real work, your technical people review access and data handling as it runs, and you see how it behaved before deciding to launch.

Decision gate: go to production, extend the test, or stop. See Test in How We Work.

06

Approvals

Nothing is built before the scope is approved, and nothing reaches production before the controlled test is reviewed. Every phase of How We Work ends with a decision you make.

In managed MARIA deployments the assistant asks before it acts where it matters, and you can see what it did and why.

04

Once it is running

Ref. TRUST_07.v1
07

Governance

Governance makes it safe. Our AI Governance service creates practical policies and controls for privacy, intellectual property, copyright and shadow AI. Where broader data privacy or technology governance matters are in scope and connected to your AI environment, they are handled inside that work.

The practice on this page applies to every engagement whether or not you buy the governance service. The service is for the policies and controls your organisation keeps.

08

Ongoing management

MARIA works differently from the systems we build for you, because it is our own framework rather than something built for one business. Where a system suits ongoing management, we host and run MARIA for you rather than handing it over, so there is no self-hosted version.

Hosting, security, data privacy support, technical support and improvement are part of the managed service, and your business data stays yours. See MARIA.

{ } Questions We Answer For Your Engagement

Some answers depend on your systems, your data and the engagement. Rather than publish blanket claims, we answer these for your specific case, in writing, before you decide.

Location

Australian by default. Which region, and where does each model vendor process?

Protection

How is data protected in transit and at rest for this system?

Retention

How long is data kept, and how is it deleted?

Vendors and models

Which vendors and models are involved, and what are the alternatives?

Visibility

Who can see what, and how are actions recorded?

If something goes wrong

What happens, and who is called?

Next Step

Zenias helps established Australian businesses use AI to increase revenue, free up capacity and build lasting capability. You work with our people, not a platform. Start with a free fit conversation.