Trust centre

What we do with your data, in writing.

This page is maintained by AlwaysOnIT to answer the security and privacy questions buyers ask before signing up. It describes the controls we operate today — it is not an independent audit or a certification.

Controls in place

Current practices

Account access

Sign-in is tied to a verified work email, with optional authenticator-app two-factor available on every account. Sessions expire and can be revoked from your account page.

Platform and hosting

The service runs on managed cloud infrastructure with UK data residency for tickets, logs and embeddings. We do not run our own hardware.

Encryption

TLS 1.3 for data in transit and AES-256 for data at rest, with per-tenant keys. We do not transmit support content over unencrypted channels.

Access to customer systems

We hold no standing administrative credentials in your tenant. Each action requests a short-lived, single-purpose token that is revoked after use.

Logging

Every prompt, tool call and credential use is written to an append-only audit record you can export at any time.

Change approval

Destructive, bulk or irreversible actions require an in-band approval from a named admin on your side before the agent executes them.

Shared responsibility

Where our job ends and yours begins

AlwaysOnIT is responsible for

  • Security of the support platform, its hosting and its data stores
  • Encryption, access control, logging and retention on our side
  • Keeping the AI agent inside its published scope and approval rules
  • Notifying you promptly if an incident affects your data

You are responsible for

  • Your own tenant configuration, licensing and backups
  • Which permissions you grant, and to which of your admins
  • Keeping user accounts, devices and MFA registrations current
  • Approving or declining the actions the agent asks you to confirm

Sub-processors

Who else touches your data

CategoryPurposeProcessing region
Cloud hostingApplication, database and log storageUnited Kingdom
Model providersAI inference under zero data-retention termsUK / EU / US
PaymentsSubscription billing and card handlingEU / US
Transactional emailAccount, billing and support notificationsEU / US

The named list, with legal entities and locations, is provided in our data processing agreement on request.

Contact

Privacy requests and security reports

Data access, export or deletion requests, and security or vulnerability reports, go to security@alwaysonit.ai. We acknowledge security reports within two working days and answer UK GDPR rights requests within one month. Good-faith research reported this way will never be met with legal action from us.

Trust centre FAQ

The questions buyers ask before they sign

Who is responsible for what between AlwaysOnIT and the customer?

AlwaysOnIT is responsible for the security of the support platform itself: the application, its hosting, encryption, access controls, logging, and the behaviour of the AI agent within its published boundaries. The customer remains responsible for their own tenant — their Microsoft 365 or Google Workspace configuration, their user accounts, their licensing, their backups, and for deciding which permissions to grant. Neither party can discharge the other's half, and any statement on this page about your environment describes what we do within it, not a guarantee about systems we do not control.

What data does AlwaysOnIT collect about my business?

We collect the account details you provide at sign-up (work email, company name, seat count), the contents of your support conversations, and the technical results of any diagnostic or fix the agent runs on your behalf. Payment details are handled by our payment provider and never stored on our systems. We do not buy data about you, and we do not sell or share your data for advertising.

How long is my data kept, and how do I get it deleted?

Support conversations and audit records are retained while your subscription is active so the agent has context on your history, and are deleted within 30 days of account closure unless a legal obligation requires us to keep a record longer. You can request export or deletion at any time from your account page or by emailing us; we respond to UK GDPR rights requests within one month.

Is my data used to train AI models?

No. Your prompts, tickets, and diagnostic output are not used to train models, ours or anyone else's. Inference runs against your tenant's context only, and our model providers operate under zero data-retention terms, meaning the request is processed and discarded rather than stored for later training.

How do I report a security issue or vulnerability?

Email security@alwaysonit.ai with enough detail to reproduce the issue. We acknowledge reports within two working days and will keep you updated until it is resolved. Please do not test against other customers' data, run denial-of-service tests, or access accounts that are not yours; good-faith research reported this way will never be met with legal action from us.

Is AlwaysOnIT certified to ISO 27001 or Cyber Essentials?

Not yet, and we will not imply otherwise. We design to UK GDPR, the NCSC Cyber Assessment Framework, and the Cyber Essentials control set, and we are working through formal certification. This page describes controls we operate; it is not an independent audit, and it is not a certification. When certification lands we will publish the dated evidence rather than a badge.

Get started

Open a chat. The AI picks up before the second ring — every time.

No onboarding calls. No sales process. Connect your devices and start raising tickets in under ten minutes.