Data handling
Data handling is where a client deployment is won or lost, and it is rarely the end users asking. Have these answers ready before the first procurement or security review, not after.
The four questions procurement asks
Residency
Enterprise can be deployed in the client own cloud or data centre, so no data leaves their environment. This is a deployment decision, not a later setting.
Encryption
Data is encrypted in transit and at rest. See security and compliance for the specifics a reviewer will want.
Retention
Retention policies and deletion rights, configurable at workspace level. Agree the retention window with the client compliance owner during scoping.
Compliance frameworks
Enterprise deployment is built to meet SOC 2 Type 2, ISO 27001, ISO 42001, and GDPR requirements.
Detail for each lives in data uses, data retention, and security and compliance. Those pages are written for a security reviewer and can be shared directly.
Training
The first question in almost every review is whether the client data trains models. Answer it plainly and early, and point the reviewer at data uses rather than paraphrasing it.
This tends to close the conversation faster than any other part of the security discussion, so lead with it.
Residency is a scoping decision
Enterprise can run entirely on the client own cloud or data centre. That is a deployment-time choice, and it is expensive to revisit once a workspace is in use and full of context.
If the client operates in a regulated sector or a jurisdiction with data localisation requirements, establish this in the first scoping conversation. Treating it as a configuration detail is the most costly sequencing mistake in an enterprise rollout.
Separation inside the workspace
Residency governs where data lives; structure governs who inside the client can reach it. Both matter to a reviewer.
Department-specific data stays separate by default, and memory is scoped by project rather than pooled workspace-wide. Combined with the permission model in roles and permissions, that is what lets a single workspace hold Finance and Design without one seeing the other. Show the reviewer the scoping model, not just the encryption posture.
Audit and evidence
Confirm the client audit requirement during scoping. Administrative activity is recorded in audit logs, and administrators can review every active project, deployed skill, connected integration, and user session from a central console. Where a client needs periodic evidence rather than on-demand visibility, agree who produces it and how often before go-live.