Security & Trust

Man using tablet for Enterprise AI Solitions

Security principles

We operate as an embedded AI layer. Partners retain customer ownership and UI control.
Payloads use system IDs rather than personal data.
Partners can audit and validate AI outputs via analytics and reporting metrics.

What we provide

Security documentation under NDA (certificates, policies, subprocessors).
API authentication and access controls.
Logging and audit trails for integration runs.

Security, compliance and trust

SolvedBy.AI is built for enterprise SaaS environments and regulated customers:

  • ISO 27001 — certified information security management, covering data handling, access control, incident response and supplier risk.

  • Cyber Essentials Plus — independently tested controls protecting against common cyber threats.

ISO 42001 — AI management system certification, demonstrating responsible governance, risk management and oversight of AI systems.

TL;DR for AI Forecasting

Ready to explore a partnership with SolvedBy.Ai?

FAQ

We are certified to ISO 27001 (information security management) and ISO 42001 (AI management), and we hold Cyber Essentials Plus. Cyber Essentials Plus is a UK government-backed certification that goes beyond a self-assessment by requiring independent technical verification that key cyber hygiene controls are correctly implemented (such as secure configuration, access control, patching, malware protection, and network boundary protections). We also undergo regular third-party penetration testing, and we can share certificates and assurance packs under NDA.

We host our platform in reputable cloud providers (e.g. AWS) using regional zones. Data residency can be aligned to your requirements (for example, EU, UK or other regions).

Your data is used to provide services to your tenant(s) only. It is not pooled to train a global model that could leak competitive information to other tenants. Any tenant‑specific fine‑tuning remains tenant‑scoped.

We use OAuth‑based authentication with scoped tokens that expire regularly. Access is segmented by tenant and region, and we can integrate with your existing identity and access management approaches where appropriate.

No—our services are designed around data minimisation. We only require pseudonymous system identifiers (e.g., employee_id, location_id) and operational metrics to produce forecasts and decisions. We do not ingest staff names, contact details, or any direct personal identifiers, and we don’t require store names or other human-readable labels. Partners keep all identifiable labels and customer-facing context inside their own platform.

The FAQ Hub is the primary self-serve knowledge base for: how the AIs work, data requirements, exogenous data options (customer/platform/partner), implementation workload, security/compliance, and commercials/pricing. It’s structured so partners can quickly find answers by platform type (ERP/WFM/POS/etc.), by engine (Forecasting/Scheduling/etc.), and by audience (engineering, product, legal, security, sales).

Our data science and research team is based in Edinburgh and includes a mix of PhDs and MScs. We regularly recruit from local universities with strong operational research, optimisation, and applied AI communities (including the University of Edinburgh, Napier, and Heriot-Watt). This team’s ongoing research focus is a key reason our forecasting and decision engines continue to improve over time.

It’s both. Most partners underestimate the UI/configuration workload: to monetise “Forecast & Decide” you need customers to configure drivers, constraints, targets, rules, and then trust and act on outputs. Data pipelines enable the AI; UI makes it valuable.

That’s ideal. The partner site is designed to slot into your existing workflow—whether you’re using IDE copilots, ChatGPT/Gemini, automated test generation, or AI-driven documentation. The goal is to provide clean reference material (FAQs, JSON patterns, UI patterns) that your tools can use to accelerate delivery without guesswork.

A practical approach is:

  • Use the storyboards to align product/UX/engineering on the end-to-end flow
  • Use the wireframes to build your UI backlog and acceptance criteria
  • Use the UI↔API mapping to implement the integration without guesswork
  • Use the partner portal’s docs/FAQs to validate edge cases, roles, and run-state handling

A common approach is:

  • Use the FAQs to confirm product decisions and integration scope
  • Use JSON examples to generate payload builders and validators
  • Use UI wireframes to generate front-end backlog items and acceptance criteria
  • Use error/status patterns to generate automated tests and monitoring checks

The partner site content is designed to support that “prompt → build → validate” loop.

Yes. We are comfortable supporting very large enterprise customers that you onboard to your platform. In those cases, we typically provide enhanced technical support, bespoke AI work and may agree additional service levels and costs, but the commercial and contractual relationship remains between you and your customer.
TL;DR for AI Forecasting

TL;DR

SolvedBy.AI is built as a secure, auditable AI layer for B2B SaaS platforms. We minimise personal data by using system identifiers, provide strong API authentication and logging, and support partner auditability through analytics and documentation. With ISO 27001, Cyber Essentials Plus and ISO 42001 certifications, SBAI meets enterprise security and responsible-AI standards while allowing partners to retain full customer and UI control.
© 2026. SolvedBy.Ai. Solved By Ai Ltd. All Rights Reserved.