SECURITY & CONTROL

Autonomy you dial in.
Never autonomy you hope for.

Intelain is built on a simple contract: humans hold the final call, the brain does only what you've explicitly allowed, everything it does is recorded immutably, and every action can be undone.

The autonomy ladder

LEVEL 1

Advisory

Recommendations only. Intelain never touches your systems; people decide and execute.

LEVEL 2

Approve-to-act

Intelain prepares the action end-to-end; a named, authorized human approves before anything runs.

LEVEL 3

Auto · low-risk

Only actions classed low-risk, only on data the brain demonstrably understands, and you choose which.

You choose the level, per company. Moving up the ladder is a deliberate act by your admins, never a default.

The control machinery

Risk classification

Every action type carries a risk class assigned at configuration time. High-risk actions require human approval at every autonomy level: no exceptions, no overrides.

Approval gates

Approvals are named and role-based: who may approve what, with a full request → approve → execute chain preserved.

Immutable audit

Every query, recommendation, approval and action is appended to an audit trail that cannot be edited or deleted: the brain's complete working history.

Readiness gate

Auto-action is gated on measured understanding. If the brain's understanding score for a domain isn't proven, it can advise there, but never act.

Rollback plans

Real-world actions ship with a prepared rollback. Undo is designed before the action runs, not improvised after.

Scoped access

Intelain reads what you connect and nothing else. Action targets are explicitly registered by your admins with scoped credentials.

Your data stays yours

Intelain's architecture keeps your data under your control: sources are connected read-only by default, credentials are vault-encrypted, and evidence queries run against your systems. We don't warehouse copies of your business to answer questions about it. Deployment options, data residency and retention are agreed per customer as part of onboarding.

As part of any evaluation, we'll walk your security team through the full architecture: the honest version, not the brochure version.

And where it runs is your choice too

Hosted by us, inside your own cloud tenant, on isolated servers with no internet egress, or entirely on one disconnected machine. Your data is never used for training, no telemetry is emitted, and the reasoning itself can run on hardware you own. In an isolated deployment, your own network monitoring can confirm nothing leaves.