Skip to content

Built for control, not blind trust.

An AI system you cannot inspect is a liability. Every Dephrast build is designed so you can see, limit and stop what it does, and so everything it did can be shown.

Eight properties, each one enforced.

Not a policy document: each of these is how the platform is built, checked by the code and its tests.

  • Least privilege

    Each agent can use only the tools it is given, within a budget checked every time it runs.

  • Approval gates

    Consequential actions wait for a person, and every decision opens on its evidence.

  • Auditability

    Every run, step, decision and model call is on the record, with its time and its cost.

  • Encrypted credentials

    Keys to your systems are envelope-encrypted at rest and never written into a trace.

  • Tenant isolation

    Each company is its own tenant, separated by the database itself on every row.

  • Access control

    Every page of the app needs a signed-in person, verified with the sign-in service on every request.

  • Controlled execution

    Anything that leaves your business goes through a port that refuses, by name, until its conditions pass.

  • Data handling

    Used only to do your work. Never used to train models. Nothing secret in a trace.

Data handling

Your data is used to do your work and nothing else. Dephrast does not train models on it. Every model call goes through one gateway and is recorded with its cost, and anything secret is redacted before a trace is written.

Where your data is processed follows from where your system runs, and it is written into your scope and your data processing agreement before anything is built.

Encryption

Credentials that connect the platform to your systems are envelope-encrypted at rest and are never written into a trace. The key that decrypts them never reaches the app you sign in to, or this website.

Every public endpoint, this site and the Dephrast app, is served over HTTPS only, with HTTP Strict Transport Security.

Access control

Every page of the Dephrast app requires a signed-in person, and identity is verified with the sign-in service on each request rather than trusted from a cookie.

The app holds one unprivileged database connection. What a person can read is filtered by the database's row-level security for their company, and the app can write only a person's own decisions, never the platform's record of what the system did.

The privileged key that bypasses row-level security never reaches any user-facing code, and this website has no database connection at all.

Tenant isolation

Each company is a tenant. Every table carries the tenant it belongs to, and row-level security is switched on for every table, so isolation is enforced by the database itself, not by application code remembering to filter.

A demonstration company shown on a sales call is an ordinary tenant with one difference, proven in code: nothing outbound can ever leave it.

Controlled execution

Each agent declares the tools it may use and a budget. Both are enforced when the agent runs, so a permission is a fact about the system, not a line in a document.

Anything that leaves your business, such as an email, a post or a posting, goes through a port. A port refuses, and says why, until every one of its conditions passes: the approval, the checks, the limits. Outbound work starts at Draft or Approve; running unattended is earned on your own records, task by task.

The workers that run agents have no public interface except the orchestrator's signed endpoint.

Auditability

Every run is recorded step by step: what it read, what it decided, how long each step took and what each model call cost. Decisions are recorded with who made them and when.

Evidence, the ledger and every decision are append-only: nothing is edited afterwards, and a wrong decision is corrected by a new one on top of it. A finance determination can be reproduced from exactly what it read.

Audit logExample

Where it runs

Every system runs on the same Dephrast runtime, with the same approvals and the same record, wherever it is deployed. Where is your choice.

What each option needs from your environment, and any enterprise requirement for infrastructure or security review, is scoped with you and written into the proposal before any work starts.

Run it where you want it.

Where it runs
Dephrast cloudYour businessAgentsRun and monitored by DephrastCRMAccountingEmail and filesDephrastEncrypted connections

Retention

Enquiries sent through this website that do not lead to work are deleted within 24 months, or sooner if you ask.

How long your documents and records are kept is agreed in the data processing agreement for each engagement, before anything is built.

Subprocessors

The services that process data for your system depend on where it runs and what it connects to, so they are named for your engagement: in writing, in the data processing agreement, before anything is built. The agreement also sets how you are told of any change to them.

Privacy and GDPR

For the systems we build and run for you, you are the controller and Dephrast is your processor, under a data processing agreement signed for each engagement.

As your processor, Dephrast is required to tell you without undue delay about a personal data breach affecting your data (GDPR, Article 33(2)). How this website handles personal data is set out in the privacy notice.

Read the privacy notice

Security review, on request

Before you decide, we walk your team through the architecture, answer your security questionnaire, and give you the data processing agreement for your engagement, with its list of subprocessors.

The questions operators ask first.

Something we haven’t answered?

hello@dephrast.comAsk on a call
Where does it run?

Wherever suits you. We can host and run it for you, deploy it into your own cloud account, or run it on your own infrastructure. Where it runs, what it may reach and which services process your data are agreed in writing before we build. Each client is its own tenant, and Dephrast does not train models on your data.

What happens when an agent gets it wrong?

Anything that would reach a customer or leave your business starts behind a person’s approval, so a wrong draft stops there, not in someone’s inbox, unless you have chosen to let that kind of work run on its own. Every run is recorded step by step, so a wrong call is traceable the same day. Where a fact is missing, the work stops and names it instead of guessing.

Can our security team review it?

Yes. We walk your team through the architecture, answer your security questionnaire and give you the data processing agreement for your engagement, with its list of subprocessors, before you decide.

Will the AI act on its own?

Only where you have allowed it, and only once its record shows it can. Every agent starts supervised; anything that leaves your business starts as a draft or a proposal a person approves. Running unattended is earned task by task, on your own records.

Ask us anything about how it works.

Bring your security questions to the assessment call, or send them ahead. You get straight answers about what the platform does, and about what it doesn't do yet.

Free, 30 minutes, and a reply from a person within one working day.