TRUST & SECURITY

Security, Data Residency, and an Audit Trail You Can Defend

Audit and forensic teams run vendor due diligence before any data moves. This page sets out how Livo systems are deployed, how client data is kept separate, and how the AI's output stays explainable and reviewable.

See the Controls →

The Controls, Stated Plainly

Every Livo system is built around these controls. Where a claim depends on your deployment choice, that is noted.

On-Premise or Private-Cloud Deployment

Systems run inside your data center or your own cloud tenant. Records, ledgers, and regulatory filings are not sent to external servers or third-party AI APIs. Air-gapped deployment is supported.

Per-Client and Per-Matter Segregation

Data, indexes, and models for one client or engagement are isolated from every other. Role-based access controls mean staff see only what their work requires.

Immutable Audit Trail

Every document ingested, query run, edit made, and flag raised is logged with timestamp, user, and source hash. The record is complete and reproducible for a client or regulatory review.

Explainable, Source-Linked Output

Each finding states the rule or pattern that produced it and links to the underlying records. No opaque risk scores that cannot be walked back to source.

Human in the Loop by Design

The system digitizes, searches, and ranks. It does not form conclusions or opinions. Every output is reviewed and dispositioned by your team.

No Training on Your Data

Client data is never used to train shared or external models. Models are configured and evaluated for your deployment and stay within it.

DPDP Rules India (2025)

Personal data of Indian data principals is processed and stored in line with India's Digital Personal Data Protection Rules, on India-based infrastructure where required.

GDPR

Systems are built to meet GDPR requirements: lawful basis, data minimisation, subject-rights support, and privacy by design.

Data Residency by Jurisdiction

Storage and processing location is configurable to the jurisdiction of the client or the matter, including India, the EU, the US, and the UAE.

Encryption in Transit and at Rest

Data is encrypted in transit and at rest using current standard algorithms. Key management follows your deployment's requirements.

Sub-Processors

On-premise deployments use no sub-processors. Private-cloud deployments use only the cloud provider you nominate, listed in the Data Processing Agreement.

NDA and DPA

Every engagement starts under a mutual NDA. A Data Processing Agreement is available on request and signed before any data is shared.

So You Can Defend the Tool, Not Just Trust It

An audit or forensic team has to be able to explain, to a regulator or a court, how a finding was reached. Livo systems are built for that:

  • Version-pinned models. The model and configuration used on an engagement are recorded and held fixed for its duration. Changes go through documented change control.
  • Logged inputs and outputs. Prompts, retrieved evidence, and generated output are stored with the engagement record, so any result can be reproduced and reviewed.
  • Evaluation before deployment. Detection rules and models are tested against a labelled sample from your data and signed off before they run on the full population.
  • Source citations on every assertion. Generated working papers and reports cite the document or ledger entry behind each statement.
  • Independence preserved. The system assists the engagement. It does not form or sign the opinion. That stays with your team.

Privacy Policy

Livo Assistant collects only the information needed to respond to an enquiry and to deliver an engagement: the contact details you submit through a form on this site, and, during a paid engagement, the data your organisation provides under a signed Data Processing Agreement.

How we use it

  • Form submissions (name, work email, company, phone) are used to schedule and follow up on a workshop or discovery call, and are stored in our CRM.
  • Engagement data is processed solely to deliver the agreed scope, under the DPA, and is not used to train shared or external models.
  • This site uses privacy-respecting product analytics to understand page usage. No engagement data passes through it.

Your rights

You can request access to, correction of, or deletion of the personal data we hold about you by emailing [email protected]. For engagement data, requests are handled through the client organisation as data controller.

Retention

Enquiry data is retained while there is a live business conversation and removed on request. Engagement data retention and deletion follow the terms of the DPA.

Terms of Service

This website is provided for information about Livo Assistant's services. The content is offered in good faith and may change without notice.

Engagements

Paid work is governed by a separate written agreement covering scope, deliverables, fees, confidentiality, data processing, and liability. Nothing on this site forms a contract or a binding offer.

Free workshop and roadmap

The workshop and roadmap are provided at no cost and with no obligation on either side. Recommendations are advisory. Any implementation is subject to a separate agreement.

Intellectual property

Text, graphics, and layout on this site are the property of Livo Assistant. Client names and quotations are published with permission.

Contact

Questions about these terms: [email protected].

Request the DPA & Security Pack

Tell us a little about your engagement and we'll send the Data Processing Agreement, the sub-processor list for your deployment option, and answers to your security questionnaire.