JOAN

Security and data sovereignty

How we protect your data and your clients’ data.

Written for the person who signs off on risk: where your data is kept, what AI may do with it, who approves and what is on record.

Security and privacy

Each person’s AI only sees what that person is allowed to see.

We set those permissions before the AI is switched on, and every request is logged.

Illustration: an adviser with access gets a sourced answer about a client’s trust; a colleague without access asking the same question is told they have no access, and nothing is shown.

Illustration. Names and details are invented.

Data sovereignty

Your systems and records stay yours.

Data sovereignty means your firm decides where its information is kept, who can see it and whose terms apply. It is one part of your firm’s sovereignty, which also covers its know-how, its memory, its approvals, its record and its choice of AI. Below is how we build for data sovereignty.

  • Your own accounts.We build in your own cloud and business accounts wherever we can, so the systems and records stay yours.
  • Your Microsoft or Google set-up.We work inside the Microsoft 365 or Google Workspace your firm already runs, with your own sign-in and permissions.
  • The region you choose.When we build in your cloud account, your firm chooses the region its systems and records are kept in. Where an AI provider processes a request is set by that provider’s terms.
  • Where AI requests go.When AI answers a question, the request is processed by the AI provider you use, such as Microsoft, Google, Anthropic or OpenAI, under that provider’s business terms.
What else stays yours

Your data and AI training

Joan does not train or fine-tune AI models on client data.

When we set up AI for your team, we use business plans such as Microsoft Copilot or Claude Team. Their terms say your data is not used to train the provider’s models unless your organization chooses to share it.

When we build in your Microsoft, Google or Claude business account, your own agreement with that provider applies, including its data protection terms.

How the controls work

People approve the AI’s work, and every question is logged.

The controls we build into each system, in plain words.

  • People approve.

    AI gathers, drafts and checks. A named person approves before anything important goes out or changes.

  • Each question is logged.

    Each question is logged for audit, with who asked and when. Floura & Co.’s connection to its inventory system works this way today.

  • Read-only by default where it matters.

    Floura & Co.’s connection to Cin7, its inventory and production system, only reads. It cannot change a record, and it shows no customer names, contacts, prices or costs.

    Read the Floura & Co. story
  • Named sign-in, no shared passwords.

    Each person signs in with their own company account, through Microsoft Entra or Google. What they can see follows your access list.

  • An audit trail your compliance team can review.

    The log shows who asked the AI what, and when, so your compliance team can check how it is used.

  • Change provider and keep your records.

    Change the AI model or the provider without starting over. We build in your own cloud and business accounts wherever we can, so the systems and records stay yours.

How we operate

How we secure our own work.

The safeguards we use in our own business, from the computers we work on to this website.

  • Dedicated, encrypted computers. We use dedicated computers for client work, with encrypted hard drives and firewalls turned on.
  • Private connections. We connect to our work through a VPN, an encrypted private network.
  • Multi-factor sign-in. Every account we use for client work has multi-factor sign-in turned on, so a password alone is not enough to get in.
  • Dedicated engineering accounts. When we hold a client’s code, it sits in our dedicated enterprise GitHub accounts, in separate repositories for each client.
  • Our site’s secrets and monitoring. Our site’s newer secrets are held in Azure Key Vault and read by the site itself, not written into code. Its health monitoring keeps no form content, email addresses, full IP addresses or browser details.
  • Reviewed releases, with a way back. Each change to our site is reviewed and tested, then released from GitHub to Azure without a stored password or key, and we keep a tested way to roll back.

If something goes wrong

  • Tell us straight away. If you see something that worries you, such as an email that claims to be from us but looks wrong, access you didn't expect, or a weakness on this site, email rebel@rebelhq.ai. Reports go straight to our founder. Tell us what you saw, but please leave client details, passwords and account information out of your report. If you report a problem to us in good faith, without accessing data that isn't yours or disrupting our services, we will not take action against you for it.

  • How we respond. We are a small, founder-led team and do not run a 24-hour desk. When we see a report, we assess how serious it is, and anything that could affect client data is worked on within an hour of our seeing it. If something is at risk, we act straight away. We shut off the affected access, change passwords and keys, and keep a record of every step.

  • We tell affected clients. If an incident affects a client's data, we tell that client within 72 hours of confirming it, and sooner when we can. They hear what happened, what it involved, what we have done and anything they should do, and we keep them updated until it is closed. If our agreement with you sets a shorter deadline, we meet it.

  • We contain it and recover. In your systems we work through your IT team; in ours we remove the cause and restore from known-good versions. We watch closely afterwards.

  • We learn and practise. After every incident, we review what happened and fix the cause. We review this plan every year and after any major change, and we will hold our first rehearsal of it by December 2026.

For your compliance team

Questions your compliance officer will ask

Plain answers. Joan builds the controls; your firm decides how they meet its own obligations.

  • Do you train AI models on our data?

    No. Joan does not train or fine-tune AI models on client data. When we set up AI for your team, we use business plans such as Microsoft Copilot or Claude Team. Their terms say your data is not used to train the provider’s models unless your organization chooses to share it.

  • Where is our data kept?

    In your own accounts wherever we can: your Microsoft 365 or Google Workspace, and your own cloud account. When AI answers a question, the request is processed by the AI provider you use, such as Microsoft, Google, Anthropic or OpenAI, under that provider’s business terms.

  • Do our workflows and AI instructions stay ours?

    Yes. We keep the instructions, checklists and skills your people rely on in your firm’s own accounts wherever we can, not in anyone’s personal account, so they stay when people leave.

  • Whose data protection terms apply?

    When we build in your Microsoft, Google or Claude business account, your own agreement with that provider applies, including its data protection terms.

  • Can the AI change our records?

    Only where you decide it should, and only with a person’s approval. Where it matters, we connect read-only by default.

  • Who can see what?

    Each person signs in with their own company account, and what they see follows your access list. There are no shared passwords.

  • Can we review what the AI was asked?

    Yes. Each question is logged for audit, with who asked and when. Your compliance team can review it.

  • What if we change AI provider, or stop working with Joan?

    We build in your own cloud and business accounts wherever we can, so the systems and records stay yours. You can change the AI model or the provider without starting over, and we hand the work over to your team.

  • How does this help us meet our own obligations?

    We build the controls and write them down: named sign-in, access lists, approvals, read-only access where it matters and an audit trail. Your compliance team decides how they meet the rules your firm follows.

Next step

Bring your compliance officer to the first conversation.

Tell us the rules your firm works under and what your compliance team needs to see. Please leave out client and account details.

Start a conversation