Security and governance
Client work stays protected.
Keep files, AI activity, approvals, and final outputs tied to the right client, team, and role.
Why it matters
Controls stay attached to every output.
Permissions, AI activity, approvals, and final outputs stay tied to the right workspace and engagement history.
ISO 27001 certified
Managed under an ISO 27001 certified security program. SOC 2 Type II is in progress.
Access control
Scope files, requests, agents, approvals, and outputs by workspace, workflow, and role.
Decision history
Every draft, comment, approval, exception, and final decision stays connected to the delivery record.
Identity and SSO
Connect enterprise identity with SSO, SAML, and role-based permissions across every workspace.
AI activity visibility
See what AI prepared, what changed, and what an approver decided on each item.
Deployment options
Discuss data residency, private deployment, and model choices with your security and CIO teams.
Security model
Security built into the way services are delivered.
Every file, prompt, output, approval, and exception stays scoped to the right workspace, role, and engagement.
Workspace-scoped access
Files, agents, outputs, and approvals are scoped by workspace and role, so users see only the engagements they can act on.
Tool and data permissions
AI actions run inside approved workflows. Teams decide what each agent can read, prepare, or update.
Prompt and output traceability
Every draft, workpaper, summary, exception, and change links back to source material.
Human approval gates
AI can prepare work, but approvals, overrides, exceptions, and final decisions remain named human actions.
Audit-ready activity logs
Access, AI activity, approvals, and outputs stay attached for risk, compliance, and client review.
No open-ended AI usage
Prompts and outputs stay inside approved workflows with the same role and retention boundaries as the work.
FAQ
Security questions
How is access scoped in FourX?
Access is scoped by workspace, role, workflow, and engagement. Files, agents, outputs, approvals, and decisions stay tied to the client work a user can see.
Can AI read every file?
Are AI outputs traceable to source material?
Who approves AI-prepared work?
What can risk and compliance teams review?
