Data & compliance
What enterprises need isn’t just “an AI that can execute” — they also need to know what it accessed, why it produced what it did, and whether it can be reviewed. Aureink spreads these safeguards across the product; this page brings them together to answer the question managers care about most: how do we keep this controllable?
1 · Governance overview
Aureink’s controllability rests on five safeguards working together, each mapping to a specific capability in the product:
| What you care about | Aureink’s safeguard | See |
|---|---|---|
| Which data it touches | It only processes files, workspaces, and organization-scoped content you’ve authorized | This page, “Data boundary” |
| Whether sensitive actions can run out of control | Permission mode + Security Center/sandbox + network access gating | Permission mode / Security Center & sandbox |
| Whether the process is visible | Which files were used, which steps were taken, and which tools were called are all reviewable | This page, “A traceable process” |
| Whether high-risk actions leave a record | Agent audit + client-side Audit Center | Agent audit |
| What employees can actually use | Everything follows Console’s grants; the client’s self-reported claims aren’t trusted | Console capability management |
2 · Data boundary
Aureink only processes content you’ve authorized: the folders you designate in a workspace, the materials attached to the current conversation, and organization-scoped knowledge granted to you in organization mode.
- It doesn’t expand scope on its own — it won’t proactively scan other directories or read unauthorized files.
- Local processing stays local — local OCR of images runs on your machine and isn’t sent to the cloud.
- Personal mode is isolated from the organization — when used personally, it reads no enterprise knowledge.
3 · Permissions and sandbox
For actions that “change the environment,” Aureink gates them through three layers to minimize risk:
- Permission mode — decides whether it asks for your confirmation before performing sensitive operations (writing files, running commands, going online); high-risk operations also get a second confirmation and a countdown lock (see Permission mode).
- Security Center / sandbox — locally constrains the executable scope of file, command, and network actions, so even automatic execution stays within bounds (see Security Center & sandbox).
- Network access — sets an allowed range for network activity, preventing tasks from reaching out arbitrarily.
4 · A traceable process
Alongside delivering results, Aureink keeps the full process: which files were used, which steps were taken, which tools were called, and what was produced are all reviewable. That means every deliverable can be traced to its source, rather than being a black-box conclusion.
5 · Audit trail
For governance, Aureink provides two layers of audit:
- Agent audit — a decision trail for dangerous operations, recording what judgment the Agent made at key points and why it allowed or blocked an action (see Agent audit).
- Client-side Audit Center — gathers usage and operation records on the client side for easy local review.
6 · Organization governance
The organization’s boundary is set uniformly by Console: what the client can use and access follows Console’s grants; the client’s self-reported claims aren’t trusted. Dependencies and permissions are resolved only against the organization capability library, and employees cannot escalate their own privileges (see Console capability management).
Statement: Aureink’s data-processing scope, capability grants, and audit standards follow your organization’s configuration in Console. Please use it within the purposes and boundaries your organization defines, and exercise caution when sensitive data or outbound actions are involved.
Last updated · July 2026 | Next: FAQ →
