Security & data
Built for businesses that read the small print.
An AI service handling IT for UK SMEs has to take security seriously. Here is exactly how we handle your data, your credentials, and your trust.
Principle
UK data residency
Tickets, logs and embeddings are stored in UK regions on AWS London (eu-west-2). Backups stay within the UK.
Principle
Encryption everywhere
TLS 1.3 in transit, AES-256 at rest. Per-tenant encryption keys, rotated quarterly.
Principle
Zero standing access
We hold no admin credentials for your systems. Each action requests a short-lived, scoped token, used once, then revoked.
Principle
Model isolation
Your prompts and ticket data are never used to train a model. Inference runs against your tenant only, with strict context boundaries.
Principle
Immutable audit log
Every prompt, tool call, and credential use is written to a tamper-evident log you can export at any time.
Principle
Approvals for risky actions
Mass changes, deletions, and off-boarding require an in-band approval from a named admin on your side before they execute.
Compliance posture
Aligned, not certified — and we say so.
We design to UK GDPR, the NCSC Cyber Assessment Framework, and the Cyber Essentials control set. We are working through formal certification and will publish dated evidence on this page as it lands. We will not claim certifications we don't hold.
Sub-processors
We use a small set of vetted sub-processors: AWS (UK), Anthropic & OpenAI (with zero data-retention agreements), Stripe (payments), and Postmark (transactional email). The full list, with locations and purposes, is in our DPA.
Trust & safety
How the agent decides what to do.
The service is built around a small number of safety rules that apply to every conversation. They define what the agent will attempt, what it will decline, and how it behaves when an outcome is uncertain.
Refuses unsafe actions
Requests that are unsafe, irreversible at scale, or capable of causing data loss are declined. This includes tenant-wide deletions, backup destruction, encryption key changes, and live ransomware response. The agent states the reason and stops.
Safe, repeatable work only
The agent works from a fixed set of tested procedures. The same issue is resolved the same way every time, against supported platforms, with each step logged. Anything outside that set is treated as out of scope rather than improvised.
Certainty before speed
When a diagnosis is ambiguous, the agent gathers more information before acting. Speed is a feature of the service, not a target that overrides safety. If certainty cannot be reached, the agent says so plainly rather than guessing.
Security
Frequently asked questions
How does AlwaysOnIT protect our user accounts?
Account protection rests on several layers. Every user must verify their work email address before gaining access, which prevents fake or unauthorised accounts being created against your company. Authentication follows current industry-standard practices, and multi-factor authentication is available to every user. Login attempts are rate-limited, and an account is temporarily locked after repeated failures so that password-guessing and credential-stuffing attacks cannot run unchecked. Access to your systems follows a zero standing access model: no long-lived credentials are held on your behalf, and access is brokered per task then withdrawn once the task completes. Identity verification runs before any account-affecting action, so persuasive chat alone can never trigger a privileged change.
Do users have to verify their email address?
Yes. Email verification is mandatory for every user before they gain access to the service, with no exception and no way to skip it. This single control removes an entire class of abuse: fake accounts, accounts created against a company by someone outside it, and sign-ups using addresses the person does not actually control. It also guarantees that password reset messages and billing correspondence reach a mailbox the user genuinely owns. When a company admin invites a colleague, that colleague verifies their own address rather than being activated on the admin's word, so the verification chain stays intact across your whole team.
Is multi-factor authentication supported and should we enable it?
Multi-factor authentication is supported for all users and takes under two minutes to enable from the account screen. It adds a one-time code from an authenticator app at sign-in, which defeats the overwhelming majority of credential-stuffing and phishing attacks even when a password has already been stolen. We make it optional rather than mandatory for standard users, because forcing enrolment during an urgent lockout can compound the problem — but we recommend it for everyone and consider it essential for anyone with administrative rights. For your own Microsoft 365 tenant, by contrast, we advise enforcing MFA for every user without exception.
How are passwords reset, and can your staff see them?
Password resets for your AlwaysOnIT account are handled securely by email. We do not reset passwords manually, and we cannot read or retrieve user passwords at any point — they are not accessible to us in a usable form. More broadly, AlwaysOnIT does not access user accounts or company data; access is controlled entirely by each company's own administrators. Reset requests are also protected against automated abuse, alongside sign-up and repeated failed logins, so an attacker cannot script their way through the reset flow. Resets inside your Microsoft 365 tenant are a separate matter and always require identity verification first.
How do you stop someone social-engineering the AI?
Social engineering is the primary attack against any helpdesk: convince the agent to reset a password or clear MFA for an account the attacker does not own. AlwaysOnIT closes this by requiring identity verification tied to the account itself — the authenticated session, the verified work email address and, where enabled, the second factor — before any privileged action. Urgency, seniority claims and persuasive framing in the chat carry no weight, because the verification step is a separate gate that either passes or it does not. CAPTCHA protection and rate limiting sit in front of sign-up, repeated login failures and password reset requests to block automated attempts.
Where is our data stored and is it encrypted?
Data is held in the United Kingdom and logs are encrypted at rest. Because no human technicians work on tickets, there is no pool of support staff able to browse your conversations, and the zero standing access model means credentials are not retained between tasks for convenience. UK data residency matters for organisations with contractual or client-imposed data-location requirements, and it is one of the most common questions raised during vendor due diligence and client security questionnaires. If you need specific written answers for a supplier assessment, raise it through support and we will respond to the individual questions directly.
Are you Cyber Essentials certified?
AlwaysOnIT is Cyber Essentials aligned by default, meaning our controls are built around the five technical control areas the scheme assesses: firewalls and internet gateways, secure configuration, user access control, malware protection and patch management. We are deliberately careful with the wording, because alignment is not certification — certification requires a verified self-assessment through an accredited body, and Cyber Essentials Plus adds a hands-on technical audit. Separately, helping your business align its own Microsoft 365 tenant with those same controls is in scope for ordinary support, and it is one of the most frequent requests we get from customers facing a client security questionnaire.
Is payment information stored securely?
Yes. Card and PayPal details are handled by trusted third-party payment providers and are never stored directly on AlwaysOnIT systems — we hold only the tokens required to bill your monthly subscription. Invoices and receipts are emailed to company admins only, so standard users never receive correspondence containing commercial detail. VAT numbers supplied for invoicing are shown correctly on invoices and handled properly for UK and EU VAT purposes. Because billing is monthly with no contract and no upfront commitment, there is never a large prepaid balance sitting on file. Billing queries should be raised through support by a company admin so they can be verified first.
Get started
Open a chat. The AI picks up before the second ring — every time.
No onboarding calls. No sales process. Connect your devices and start raising tickets in under ten minutes.