TRUST & LEGAL · SECURITY
EdenTouch AI Governance Delivery OS is designed around workspace separation, Microsoft-backed identity options, client-controlled storage, and clear activity visibility. This page explains the security principles the platform is built on — and what still sits on the roadmap.
Each client workspace is designed to hold its own records separately. AI systems, evidence, actions, and reports for one client should not appear in another client's workspace.
Access within the platform is designed to reflect the user's role. Consultants manage their own workspaces and control who can view or edit client records.
Where enabled, users authenticate with their existing Microsoft 365 identity. Credentials are managed by Microsoft — the platform does not store your Microsoft password.
Where SharePoint is connected, evidence documents upload to the client's own Microsoft environment. The platform holds a reference only — the document belongs to the client.
Where OneDrive is connected, reports export directly to the consultant's personal Microsoft storage. The platform does not retain the exported file.
Key governance actions — risk assessments, vendor evaluations, decisions, quarterly reviews — are tracked within the platform. This creates an auditable record of delivery activity for each client workspace.
Platform security works best when users make thoughtful decisions about access and data. Here is what responsible use looks like:
The Microsoft sign-in, OneDrive, and SharePoint integrations depend on the user's Microsoft account settings, their organisation's tenant configuration, and the permissions granted at connection time. Access and permissions are managed within Microsoft's own systems — EdenTouch does not control or override Microsoft's access policies.
These features are planned or under active review. They are not yet live in the current beta version.
This page provides a plain-English overview of security-related product features and design principles. It does not represent a formal security certification, a penetration test report, or a compliance guarantee of any kind. Organisations with specific security, audit, or data residency requirements should assess suitability with their own IT and security teams.
Privacy Preferences
We use essential cookies to run EdenTouch. With your permission, we may also use analytics and session recordings to improve onboarding, fix errors, and understand where users get stuck. Session recordings are for product improvement only and are not used in governance reports or client assessments. Privacy & Data Policy