Scope the information involved
Identify which traveller, guest, booking and operational data the workflow actually needs. Agree the permitted sources, environments and retention requirements. Use redacted or synthetic examples where appropriate during early assessment.
Do not send credentials, payment details, passport records or sensitive customer files through this website. Contact the team to agree an appropriate transfer and access process.
Confirm controls with evidence
- Access roles, approval owners and access-revocation procedures.
- Encryption and environment configuration for the agreed deployment.
- Logging, monitoring, change management and incident responsibilities.
- Model/provider data terms, subprocessors, retention and training-use settings.
Keep AI authority separate from input
A retrieved document or customer message should not grant a system additional permissions. Identify the actions a tool can take, which require human approval and how failed or uncertain actions are reconciled.
These are design requirements to agree and verify for the implementation. Their inclusion here does not assert that every historical Appnox deployment has the same controls.
Compliance and certification status
No SOC 2 or ISO 27001 certification, universal data-residency guarantee or blanket regulatory compliance is asserted on this page. Request current evidence directly from Appnox where procurement requires it.
Data-processing terms, cross-border handling, hosting location and contractual commitments need to match the actual project and providers. Review the applicable legal and contractual documentation with your team.