Trust & governance

Trust the analysis. Control the data.

Management intelligence is only worth acting on when access to the data is controlled, the calculations follow rules the business agreed, and every material finding can be traced back to the figures behind it. That is the standard HENIOCHOS is built to.

  1. 01

    Data access

    Authenticated, tenant-scoped access to the client's own data

    Access controlled

  2. 02

    Business rules

    Agreed KPI definitions, periods, hierarchy and thresholds

    Rules first

  3. 03

    Validated analysis

    Deterministic calculation on an approved dataset

    Calculated

  4. 04

    Evidence

    Figures, period and context retained behind each finding

    Traceable

  5. 05

    Management decision

    People decide; the analysis supports the decision

    Human control

The trust model runs in one direction: access, then rules, then calculation, then evidence — and the decision stays with your management team.

Four pillars

Trust is a structure, not a statement.

Four things have to hold at once: your data stays yours, the rules come before the answer, the evidence stays visible, and the decision stays human.

Data isolation & access control

Each client environment is kept separate, and access is governed by the authenticated user and their organisation — enforced at database level rather than only in the interface.

  • Tenant-scoped authorisation with row-level security in production
  • Views scoped to the role the business has granted
  • Raw import infrastructure restricted to platform administrators

Rules before AI

Canonical KPIs are defined with your business and calculated deterministically. The language layer explains results; it does not create them.

  • Definitions, periods and hierarchy agreed before analysis relies on them
  • AI does not invent canonical metrics or bypass agreed rules
  • Thresholds for what counts as material are set by management

Evidence & traceability

Material findings carry the figures, period and context they came from, so management can verify a statement instead of accepting it.

  • Findings tied to the underlying figures and comparison period
  • Fact, inference and unknown kept visibly distinct
  • Unsupported causes are not presented as facts

Human decision control

HENIOCHOS is analysis and decision support. It surfaces what changed and what deserves attention — your team decides what to do about it.

  • No autonomous business actions
  • Priorities are proposed, never enforced
  • Judgement, context and accountability stay with management

Security controls

Security controls that are enforced, not merely stated.

These are technical controls applied in the production platform and checked as part of our internal security baseline — described plainly, without certification claims.

Row-level access controls in production

Data access is restricted at database level, scoped to the authenticated user and their organisation.

Raw imports are platform-admin only

Raw import infrastructure is restricted at both application and database level, even for clients with full access to their own analytics.

Private raw import storage

Import storage is private, with no anonymous access policies.

Anonymous privileges removed

Anonymous privileges were removed from production business and security tables in the latest permission-hardening step.

Internal administration is not publicly callable

Administrative operations are not exposed for anonymous execution.

EU-region production database

Production database infrastructure is hosted in an EU region (Ireland).

Technical evidence note: at the latest verified baseline, row-level security is enabled across 49/49 current public production tables. Two anonymous verification endpoints remain public by design, so that a code issued on an evidence record can be checked without an account.

Verifiable evidence

Security claims you can check, not just read.

When a security or control check is completed, HENIOCHOS issues an evidence record into a security evidence register. Each record carries a unique HEV code, the date and platform revision it refers to, a public-safe summary of what was checked, and a SHA-256 integrity reference.

  • A record is created from a completed control check — never from an intention.
  • The HEV code identifies exactly one record.
  • The integrity reference lets the record be matched byte-for-byte against the register.
  • Verified records currently exist for the security baseline and for client data isolation testing.

Security evidence verification is available on request during evaluation. The public verification portal goes live with the production domain.

Security evidence record

Example format
Evidence code
HEV-YYYY-XXXXXXXXXXXXXXXXXXXX
Record type
Security baseline / control check
Date
YYYY-MM-DD
Revision reference
Platform revision at time of check
Public summary
Public-safe description of what was checked
Integrity reference
SHA-256 · 64 hexadecimal characters

Illustrative format only. This is not a verified record and contains no live values. Evidence records are issued from completed control checks and can be matched against the HENIOCHOS security evidence register.

Deletion & offboarding

A clear exit matters as much as a secure start.

Offboarding should be as evidenced as onboarding. HENIOCHOS is designed so that removal of production data can be measured and recorded, rather than promised.

01

Access can be revoked

Client access to the environment can be withdrawn at the point offboarding begins.

02

Data inventory can be measured

What is held in production for that client can be inventoried before anything is removed.

03

Zero-state can be verified

Production database and storage can be checked for a zero state as part of offboarding, rather than asserted.

04

A deletion record can be issued

The HDC certificate architecture supports a verifiable deletion record with an HDC code and SHA-256 integrity reference.

This is a verification framework available as part of an offboarding process — not a self-service purge button. Production purge verification and infrastructure backup-retention status are reported separately, with retention periods stated precisely rather than implying that every backup copy disappears immediately.

Data residency

Production database infrastructure is hosted in an EU region (Ireland).

Data residency is one part of a wider governance picture. Security and privacy controls across the services HENIOCHOS relies on are assessed as part of our governance model, and we do not claim that every external service or subprocessor operates exclusively within the EU. Where residency matters to your organisation, we will walk through the specifics during evaluation.

Analytical governance

Why an answer can be trusted.

The order matters. Authorised data is validated, business rules are applied, KPIs are calculated deterministically — and only then does the AI analyst explain what the numbers show. AI is not the source of your canonical KPIs.

  1. 01

    Authorised data

    Only data the client has provided and permitted.

  2. 02

    Validation

    Structure, completeness and consistency checks first.

  3. 03

    Business rules

    Agreed definitions, periods, hierarchy and thresholds.

  4. 04

    Structured analytics

    Canonical KPIs calculated deterministically.

  5. 05

    AI explanation

    Language layer explains results it did not invent.

  6. 06

    Human decision

    Management interprets, judges and decides.

Facts are calculated before they are explained.

Unsupported causes are not presented as facts.

Evidence remains visible behind material findings.

Unknowns are identified rather than invented.

Plain speaking

What we do not claim.

Precision is part of the product. The limits we state are as deliberate as the controls we describe.

We do not claim any system is risk-free.

We describe the controls that are in place and the evidence behind them, and we keep improving them.

We do not present planned assurance work as completed evidence.

Only checks that have actually been performed become evidence records.

We do not treat AI output as a substitute for authorised data and business rules.

The rules and the approved dataset remain the source of truth for every canonical number.

We do not describe integrity references as signatures.

A SHA-256 value is an integrity reference that proves a record has not changed — nothing more.

Bring your data. Keep control.

See how HENIOCHOS applies your rules, isolates your data and keeps the evidence behind every material answer.