Security, from the first assessment.
Edgerton collects the information you agree to share so we can understand your work. We provision a dedicated database for your assessment, isolated from other customers. If you choose a build, Edgekeeper runs on a dedicated Microsoft Azure server with controlled access to your business tools. Here is what each product collects, who can access it, and how we protect it.
Security is part of the service from day one. We review your deployment’s controls with you and your IT provider before the engagement begins.
Does Edgerton share a database with other customers?
We provision a dedicated database for your business before the assessment begins. It is isolated from other customers and reserved for your assessment records. Authorized access is limited to delivering and supporting your engagement.
What can Edgerton collect?
You agree the computers and collection level before installation. Activity covers apps, window titles, and active or idle time. Workflow adds screen context. Meeting audio needs the additional consent agreed for Full Picture. Your team is told what is collected and why.
What happens after the assessment?
Collection ends with the agreed measurement window. You keep the report and proposal. Captured assessment data is hard-deleted five business days after report delivery under the engagement terms; retention for reports and backup copies is described separately.
What database security standard do you follow?
Every customer deployment includes our database security standard: 24 controls covering access restrictions, isolation tests, credential storage, connection settings, backups, and database maintenance. We configure and verify the controls before your engagement begins. Ask us for the verification results for your deployment.
Where does Edgekeeper store our data?
Your records, conversations and business memory are stored in a database scoped to your business. The dedicated Edgekeeper server runs in our Microsoft Azure account and accesses those records through controlled tools. It has no public internet address. Your data and accumulated business knowledge are yours, with full export rights in the contract.
Can Edgekeeper change anything in my systems?
Not on its own. Every question is narrowed to read-only before it runs, so the brain is never holding a credential that could change something. A change happens only after a person on your side approves one specific action, and that approval is good for exactly one action, once.
What does Edgekeeper actually see?
Only what the person asking is allowed to see, and only what a specific question asks for. We never bulk-ship your data to a model. It asks narrow questions of your systems, one at a time, and every one of those looks is written down where you can read it. Passwords and keys are never part of the conversation.
Who on my team can see what in Edgekeeper?
You decide, by area — service, money, sales, company records, equipment, projects, people — and the database itself enforces it. Someone without the money area gets nothing where a billed figure would be, and neither does the brain when it answers for that person. It is not a rule the AI is asked to follow. The information never reaches it.
What if someone tries to trick Edgekeeper?
We assume they will, through the text it reads — a message, a device name, an attached document. Every piece of text that comes out of your systems is wrapped and labelled as information rather than instruction before the brain sees it, and its standing rule is that only your people can authorise an action. We ran that attack on purpose and published what happened.
What happens if the Edgekeeper server is attacked?
Each question runs in a throwaway sandbox. Outbound requests can reach only named destinations through a controlled gateway; unrestricted internet access is blocked. These limits reduce exposure but do not make an attack impossible. The machine itself is held to a written standard of checks, and one that fails a check is not allowed to run. The record of what happened leaves the machine every ten minutes, to somewhere the machine cannot reach back into.
What about HIPAA and audits?
We hold no external audit report and no certification, and we would rather say so than let a badge imply one. What we have is a written standard of controls, each with what it prevents and the check that proves it. For practices handling patient records the condition is explicit: we deploy on the API tier under a zero-retention agreement, and the paperwork is signed before any patient data moves.
What happens to our data if we stop working together?
You leave with it. Your records, everything the brain has learned about how your business runs, and the log are yours, with full export rights written into the contract from the first day. Leaving is a documented handover and we help you move it. The server and the Edgekeeper software stay ours to run.
Found something wrong with any of this? Tell us and we will fix it and say what we fixed.
Write to security@automatededge.ai. If you would rather talk through how this applies to your own practice, the call is free and there is no pitch.
Free · 30 min · no pitch. Or read what Edgekeeper actually is.