---
title: "AI Security & Trust | Margins"
description: "Your AI should belong to your business — architecture designed so you keep control of your data, infrastructure and business intelligence."
url: https://margins.agency/technology/security-trust
---

Security & Trust

# Your AI should belong to your business.

Enterprise AI can touch some of the most valuable information inside a company — customer data, operational knowledge, internal processes and proprietary decision-making.

Margins designs AI and software systems around the principle that customers should retain control over their data, infrastructure and business intelligence.

- Talk to our team

- Discuss your requirements

Your infrastructure. Your data. Your intelligence.

Our principle

## Your business data is not a commodity.

AI becomes substantially more valuable when it understands the company using it.

That information is not simply input for an AI system. It is part of the company’s competitive advantage.

What AI learns about a business

- Its customers.

- Products.

- Processes.

- History.

- Documents.

- Decisions.

- Operational patterns.

- The knowledge accumulated by its people.

Don’t move your business into someone else’s AI environment. Bring AI into yours.

Architecture

## Security decisions start before the first line of code.

Rather than treating security as something added before launch, we consider data boundaries, access, infrastructure and external dependencies when designing the system.

01 · Data

### Where does information live?

Understand what information the AI needs, where it currently resides and where it is permitted to move.

02 · Models

### What receives that information?

Select models and deployment approaches according to the sensitivity, performance and operational requirements of the use case.

03 · Access

### Who and what can interact with the system?

Design authentication, authorization and system boundaries around the actual users and workflows.

04 · Infrastructure

### Where does the system run?

Deploy according to the customer’s technology environment and requirements rather than forcing every implementation into the same architecture.

Security is an architectural decision before it becomes an operational control.

Deployment

## One architecture doesn’t fit every enterprise.

Different businesses have different requirements around infrastructure, data residency, existing technology and internal control.

### Customer cloud

Deploy into the customer’s existing cloud environment and infrastructure.

### Private cloud

Use isolated infrastructure where additional separation and control are required.

### On-premises

Run components within customer-controlled infrastructure where operational requirements demand it.

### Hybrid

Keep sensitive systems or data inside controlled environments while connecting approved external services where appropriate.

Architecture should follow the requirements of the business — not the convenience of the technology provider.

Data boundaries

## Every AI architecture creates a data path.

Instead of treating AI as a black box, the architecture should make the path clear — from where data originates to what returns to the business.

If a system uses your most valuable information, you should understand exactly where that information goes.

1. 01 **Where data originates**

2. 02 **What information enters the AI workflow**

3. 03 **Where processing happens**

4. 04 **Which models or services receive information**

5. 05 **What gets stored**

6. 06 **What gets logged**

7. 07 **Who can access it**

8. 08 **What returns to the business**

Model strategy

## Use the right model for the data, not just the most convenient model.

Enterprise architecture should allow model choices to be made intentionally. Depending on the use case, a system may use:

01 **Hosted frontier models**

For workloads where their capabilities and approved data boundaries make sense.

02 **Privately deployed models**

Where greater infrastructure and information control is required.

03 **Open-source models**

Where ownership, customization or deployment flexibility matters.

04 **Specialized models**

For prediction, classification, vision or other domain-specific tasks.

Model selection is an architecture decision, not a brand decision.

Access control

## AI shouldn’t become a shortcut around existing permissions.

An employee shouldn’t gain access to information through an AI assistant that they wouldn’t be permitted to access through the underlying business system. Depending on the implementation, that design principle can involve:

- Authentication

- Role-based access

- User permissions

- System permissions

- Data-level restrictions

- Environment separation

- Service credentials

- Auditability

Example · Sales manager Business system AI assistant

Customer pricing ✓ ✓

Payroll records ✕ ✕

Own team’s pipeline ✓ ✓

Board documents ✕ ✕

AI should respect the boundaries of the business systems it connects to.

AI-specific risk

## Secure infrastructure is necessary. It isn’t sufficient.

AI systems introduce behaviours that conventional applications don’t always have — so they require controls beyond conventional application security.

- ! Outputs can be incorrect.

- ! Models can behave unpredictably around unusual inputs.

- ! Retrieval can surface inappropriate information.

- ! Agents can be given access to tools and actions.

- ! Prompt injection can attempt to manipulate system behaviour.

- ! Sensitive information can unintentionally enter AI workflows.

- ! Model behaviour can change when underlying services change.

1. 01 **Control the input** — Understand what information can enter the system.

2. 02 **Control the context** — Determine what data the AI is allowed to retrieve.

3. 03 **Control the tools** — Limit which systems and actions AI can access.

4. 04 **Control the output** — Validate, structure or review outputs where appropriate.

5. 05 **Control the action** — Require human approval where the consequences justify it.

6. 06 **Observe** — Maintain visibility into what the system is doing in production.

The more autonomy AI receives, the more important the controls around it become.

Human-in-the-loop

## Not every decision should be delegated to AI.

The right level of autonomy depends on the consequence of being wrong. A content suggestion may need little oversight; a financial decision may require explicit approval.

01

### Assist

AI recommends. Human decides.

02

### Prepare

AI prepares the action. Human approves.

03

### Act + review

AI acts within defined boundaries. Human reviews exceptions.

04

### Automate

AI acts automatically within controlled conditions.

Less autonomy Evidence → More autonomy

Autonomy should increase with evidence, not ambition.

Visibility

## If AI affects the business, you need to understand what happened.

Production AI should provide enough visibility to investigate system behaviour when something goes wrong — requests, workflow execution, model calls, retrieved information, tool usage, decisions, errors, human intervention and performance.

A system you can’t observe is a system you can’t responsibly operate.

Trace · illustrative req\_7f3a

1. 09:14:02.118 **User request** “Which customers show declining orders this quarter?”

2. 09:14:02.140 **Access check** Role: Sales manager · Region: North

3. 09:14:02.205 **Context retrieved** 3 sources · scoped to user permissions

4. 09:14:02.891 **Model call** Model routed per policy

5. 09:14:03.010 **Tool usage** ERP query · read-only

6. 09:14:03.420 **System decision** 12 accounts flagged

7. 09:14:03.433 **Human intervention** Review requested for 2 accounts

8. 09:14:03.440 **Performance** 1.3 s · within threshold

Production operations

## Trust has to survive production.

The environment changes after launch. That’s why Margins’ responsibility can continue after go-live through Managed AI — monitoring production systems for the signals required to understand whether they remain healthy, reliable and fit for purpose.

[Explore Managed AI](https://margins.agency/services/managed-ai)

- Models change.

- Dependencies change.

- Users change.

- Data changes.

- Integrations change.

- New failure patterns emerge.

Operational control

## Visibility and control across production AI.

Rivermind is Margins’ proprietary AI Operations Platform. It connects models, data, tools, business rules and workflows while providing the orchestration and operational control required to manage AI in production.

- Orchestration

- Rules

- Workflow control

- Model routing

- Operational visibility

- Human intervention

[Explore Rivermind (opens in a new tab)](https://getrivermind.com/)

Built for your business

## The intelligence you create should compound inside your company.

The more AI understands about your operations, customers, processes and organizational knowledge, the more valuable that intelligence becomes. Margins builds enterprise AI around the customer’s business environment rather than creating unnecessary dependency on a proprietary SaaS workflow.

The objective is not to make your business dependent on Margins. It’s to make your business more capable because of what we’ve built together.

Our principles

## Trust is designed into the system.

1. 01 **Control** — Know where your systems, data and AI operate.

2. 02 **Minimization** — Give AI access to what it needs — not everything available.

3. 03 **Separation** — Maintain appropriate boundaries between users, systems and environments.

4. 04 **Observability** — Be able to understand what the system is doing.

5. 05 **Human oversight** — Keep people in control where consequences justify it.

6. 06 **Ownership** — Build organizational intelligence that strengthens the customer rather than creating unnecessary dependency.

Your requirements

## Start with the constraints.

Every enterprise environment is different. Before architecture is finalized, we work to understand the relevant requirements.

**Have specific security, infrastructure or data requirements?** We’ll design the architecture around them.

- Data sensitivity

- Infrastructure

- Existing cloud environment

- Internal systems

- Identity and access

- Third-party services

- Model providers

- Data residency

- Operational risk

- Human oversight

- Legal and compliance requirements

We don’t assume what your security requirements are. We design around the requirements your business actually has.

End-to-end

## Security decisions happen throughout the implementation.

1. 01 **Discover** Understand the business information and processes involved.

2. 02 **Design** Define architecture, data boundaries, access and deployment.

3. 03 **Build** Implement the system around those controls.

4. 04 **Deploy** Move into the approved production environment.

5. 05 **Train** Ensure users understand how the system should be used.

6. 06 **Adopt** Establish responsible operational behaviour.

7. 07 **Operate** Monitor production performance and system health.

8. 08 **Improve** Adapt as technology and business requirements change.

Security isn’t a gate at the end of delivery. It’s a design constraint throughout it.

Why Margins

## One partner across the system.

Security and trust depend on how AI interacts with software, data, infrastructure, integrations, users and business processes. Margins brings those disciplines together.

01

### AI Engineering

Understand the models, agents, retrieval and intelligence.

02

### Software Engineering

Engineer the applications and services around them.

03

### Data & Infrastructure

Design the environments and information flows behind them.

04

### Enterprise Integration

Connect AI to existing systems without treating the business as a greenfield environment.

05

### Training & Enablement

Help employees understand how to use new capabilities appropriately.

06

### Managed AI

Maintain visibility after the system enters production.

One architecture. One accountable engineering partner.

Technical due diligence

## Have security or architecture questions?

If you’re evaluating Margins for an enterprise AI initiative, bring your technical, infrastructure and data requirements into the conversation early. We’ll walk through the proposed architecture, deployment model, data boundaries and operational approach with your technical stakeholders.

Discuss your requirements

Build AI on your terms

## Bring AI into your business without giving up control of what makes it valuable.

We’ll work with your technical and business teams to design an architecture around your systems, data, operational requirements and risk profile.

[Talk to our team](https://margins.agency/contact)

[Explore AI Engineering →](https://margins.agency/services/ai-engineering)
