Security & Trust

Your data stays yours.

We built Animus for UK businesses that take privacy seriously. Here's exactly how we protect your data and your customers'.

Simple commitments.

What we do

  • Encrypt all data in transit (TLS 1.3) and at rest (AES-256)
  • Isolate every customer's data — no cross-tenant access, ever
  • Store all data on UK-based servers
  • Inject credentials server-side — your API keys never reach the AI model
  • Let you revoke all access in one click
  • Maintain full audit logs of agent activity

What we don't

  • Use your conversations to train AI models
  • Sell or share your data with third parties
  • Store customer PII longer than necessary
  • Give any AI model direct access to your credentials
  • Log sensitive data passed through agents unless you ask us to

Compliance status.

StandardStatusNotes
UK GDPR
Compliant
Data stored in UK, DPA available
ICO Registration
Registered
Registration number available on request
TLS in transit
Enforced
TLS 1.3 minimum
AES-256 at rest
Enforced
All customer data encrypted
SOC 2 Type II
In progress
Audit initiated Q2 2026
ISO 27001
Planning
Target: Q4 2026

AI handled responsibly.

No training on your data

Your conversations, leads, and customer messages are never used to train or fine-tune AI models. What goes into your agent stays in your agent.

Credential isolation

Your API keys, CRM tokens, and integration credentials are injected at the server level. The AI model never sees them.

Per-tenant isolation

Every Animus deployment runs in its own isolated environment. One customer's data cannot be accessed by another, by design.

Human escalation

Agents are configured to recognise their limits. When a query falls outside scope, the agent escalates to a human — it never guesses with sensitive matters.

Security question? Ask us.

We're happy to share our full DPA, answer specific compliance questions, or discuss enterprise security requirements.

Start Free Trial