Your IT team can sign it off.
IT and cyber security decide whether anything is deployed. Discovery gives them what they need to review it properly, early, and alongside everyone else.
How it is built
- Detection runs on the person’s own phone, including the AI models.
- Message content never leaves the phone unless the person chooses to share it.
- What reaches our servers is de-identified signal: flag counts and categories, no content and no identities.
- Each messaging account is connected by the person, with its own consent. Nothing sweeps the device.
- When someone escalates, the evidence package is hash-anchored and tamper-evident.
What stays with you
- Identity and account management. We never hold or ask for staff account credentials.
- Who receives escalations, and through which of your systems.
- Data residency for anything your deployment stores, set during discovery.
- The decision to deploy, after your own review.
What your team receives in discovery
Architecture review pack
Components, what runs on the device and what runs on servers, and how they connect.
Data-flow maps
Every flow from the phone outward, what it carries and what it never carries.
Security questionnaire
Your standard vendor questionnaire, answered, with evidence attached.
Independent verification
Scope agreed for third-party audit of the privacy claims, so you are not relying on ours.
How an engagement runs
Each step is its own decision. You only go further when the last one has earned it.
Desktop audit
A short review of how harm reaches your people today, from your intake answers and a call.
Request a briefing ›Audit & organisational plan
Your departments mapped against the harms and obligations in scope, checked against a framework built with specialist employment counsel.
A private first cohort
Around ten people, fully private, with no automatic escalation. Training and hands-on onboarding included, measured against a baseline.
Policy & escalation
Your policies built into the escalation pathways, mapped with counsel and your broker, so the board can show its obligation is met.
Twelve-month term
Quarterly reviews, threshold tuning, refresher training and a board report on what the control is doing.
Ready to get started?
Bring your IT and cyber team into discovery from week one. Their sign-off is part of the plan.
