Security, control & ownership
Security, control & ownership
Sapphire I.C.D.S. keeps a server-enforced boundary between users, AI and business operations. Your organization defines hosting, permissions, access policies and the data lifecycle, while significant actions remain revocable and auditable.

What stays under your company’s control
Business data and rules
Operational records, documents and settings are separate from the rights to the platform. The customer controls the content, retention periods, export and access to it.
Hosting environment
The platform runs on customer infrastructure or on Sapphire hosting. Administration, backups, updates and areas of responsibility are agreed before launch.
Licence and rights
Sapphire I.C.D.S. and its modules are supplied under licence; source code and exclusive rights are not transferred automatically. This does not restrict the customer’s ownership of its business data.
How every action is checked
The interface is not the security boundary: the server confirms permission in the current context.
- 1
Establish identity and session
The account, active session, device and the surface available to the user are checked.
- 2
Check role and policy
The current group, permissions, connection scope and tool status are taken into account.
- 3
Validate operation and data
The module validates the action, record owner, permitted fields and expected state.
- 4
Execute and record
The result is linked to the user, session and tool; critical actions require separate confirmation.
AI without universal access
Only explicitly published tools
The model sees a limited catalogue of permitted operations, not direct access to the database or internal functions.
Read, change and delete are separated
Permissions and scopes separate data retrieval, writing and critical actions. A user cannot extend the boundaries set by an administrator.
Internal and external contours stay independent
A tool available to the built-in assistant does not automatically become available through external MCP. Connections are published, limited and revoked separately.
Security you can operate
Sessions and devices
Employees can see their active connections; an authorised administrator can end one session or all sessions according to company policy.
Recovery and access revocation
Single-use codes and limited lifetimes protect recovery. After a role or password change, or a confirmed risk, old access is terminated by the server.
Auditing without secrets
Significant events are linked to the subject, time and action. Passwords and full tokens do not enter the log, and access to audit data is authorised separately.
Tell us what must remain inside your environment
Specify the hosting model, data types, user groups, external connections and actions AI may perform. We will propose a clear access, responsibility and implementation model.