Skip to content
ASKIQ

It reads everything.
That is the part to get right.

An assistant that can reach every system in the company is either the most useful thing IT has deployed this year or the largest hole they have opened. The difference is entirely in how access, residency and auditing are handled, so those are stated here plainly rather than summarised as a badge.

Three places it can run

The question is not whether your data is safe in the abstract. It is where, precisely, it is.

Hosted

We run it. Your systems are reached over encrypted connections with read-only credentials you issue and can revoke at any time.

  • Nothing to deploy
  • Fastest to start
  • Credentials stay revocable by you

Your cloud tenancy

Deployed inside your own cloud account. The infrastructure is yours, the data path never leaves it, and your existing controls and monitoring apply.

  • Your account, your region
  • Your network controls apply
  • Your monitoring sees it

Self-hosted

Runs entirely on your infrastructure, including on-premises. For organisations whose data is not permitted to leave the building at all.

  • Nothing leaves your environment
  • On-premises supported
  • Air-gapped options on request

Where your data lives

Nothing is migrated

Sources are read in place. There is no copy of your business sitting in a second system that then has to be secured, kept current and eventually deleted.

Three deployment models

Hosted by us, deployed inside your own cloud tenancy, or fully self-hosted on your infrastructure. The third means nothing leaves your environment at all.

Never used for training

Your data is not used to train any model. It is read to answer the question in front of it, and that is the extent of it.

Who can see what

Your permissions, inherited

Access is evaluated against the underlying system. If a person cannot open a record today, asking about it here does not reveal it.

Read-only credentials

Connectors ask for the least access that answers questions. Write access is not required and is not requested by default.

Single sign-on

Staff sign in with your existing identity provider, so joiners and leavers are handled by the process you already run.

What you can prove afterwards

Every question logged

Who asked, what they asked, when, and which systems were read to answer it.

Answers traceable to source

The working log is retained with the answer, so a figure quoted in a meeting can be traced back to the records behind it.

Connector-level visibility

Which systems are connected, what each one is permitted to read, and when it last did so.


What we do not claim

Plenty of security pages imply certification without stating it. These are the honest boundaries, and we would rather you read them here than discover them during procurement.

  • No certification claimed

    We do not hold SOC 2, ISO 27001 or equivalent certification and do not imply otherwise. If your procurement requires one, tell us early and we will be straight with you about where that stands.

  • A language model is involved

    Answers are generated, which means the working log is not a nicety. It is how you verify, and it is why every figure is traceable to the records behind it.

  • Read access is real access

    Read-only is not the same as harmless. Connect it to what it needs, review the audit trail, and treat its permissions with the seriousness you would give any account that can read that data.

  • No customer references yet

    There are no logos on this site because we have not been given permission to use any. What we can offer instead is the demo and a scoped pilot on your own data.

Questions we have not answered here

Send them over. A technical conversation early is cheaper for both of us than one during procurement.

Ask us directly