Approval before setup.
Intake asks the sponsor in writing before a project is created. Plan approval is a second, separate gate. See the case →

Trust and control
Know what Viti can read. Decide what it can do. Stop it in one action.
Runs inside a boundary you control: your governance, your data. Revoke the licence and it stops, shuts down and wipes its workspace.
A dedicated user you authorise, scoped to what you allow. Audited, revocable in one action. Mail and calendar read-only.
AES-256 at rest, decrypted only in memory. The key is split in three parts held separately; the files alone are useless, to us included.
Names, addresses and numbers are redacted before any text reaches the model. The model sits outside: a socket, swappable, keeps nothing.
Control you can see in the cases
Intake asks the sponsor in writing before a project is created. Plan approval is a second, separate gate. See the case →
The analysis names who decides and records the response under the same ID. See the case →
A breach reaches the account team first. The CEO only when severity or silence crosses the rule. See the case →
At setup, in writing
Three things are settled with you before Viti reads anything.
Where Operating Memory is stored, what is sent to the model after the PII gate, which provider, what is logged, and for how long.
AES-256 at rest, decryption in memory only, and which of the three key parts sits with you.
Revoking the licence shuts Viti down and wipes its workspace. Which records you keep, and how the identity's access ends, is written down.