Data & Security
Your data has one home.
Your security has one standard.
Yours.
Agents run on your enterprise AI. TP Warehouse runs in your cloud. Both work to the standard your team sets.
No detour through us
What we deliver travels to you, never the reverse. Here is each data path, end to end.

Agents on your enterprise AI
An agent is a set of instruction files: procedures, knowledge, and guardrails written as readable text. Both work inside your environment. Managed Agents run on the enterprise AI you already use, with instructions and templates we maintain. Private Agents go deeper: infrastructure you control outright, customization end to end.
- Prompts and files go to your AI platform, nowhere else
- Model traffic runs under your existing agreement with your AI vendor
- Every instruction is text your team can review before installation
- Reference content arrives as read-only downloads from public sources
- Secured by the enterprise controls your platform already enforces

TP Warehouse in your cloud
TP Warehouse deploys as a dedicated instance in your own cloud or a third-party environment you choose. One deployment per customer, with its own database. It connects to your ERP and CPM through the connections you approve, API, file-based feeds, or a mix. Your figures land there and stay there.
- A dedicated deployment, never shared
- Agent model calls go to the model vendor you configure
- Every figure drills down to the source transaction
- The audit trail records who changed what, and when
- Hardened at implementation, from encryption to sign-in
What agents may do.
Whether agents work on your enterprise AI or inside TP Warehouse, every deployment we implement carries a governance layer, configured with your team before agents touch real data.
Enforceable Rules
What an agent may read, write, and run is set in policy your team approves: allowed, denied, or routed to you for sign-off. Enforced in code, not just written in instructions.
Named and Accountable
Every agent acts under its own identity. Every action lands in the audit trail with a named actor, so any figure or change traces back to who did it, and when.
Stoppable and Reviewable
Sensitive steps wait for your approval. Any agent can be halted at once, and the trail exports as evidence for your own reviews.
Controls and certifications.
Private deployment
Private is the default: agents run on your enterprise AI, TP Warehouse in your cloud. Private Agents go deeper still, putting the full stack on infrastructure you control outright: your region, your identity provider, everything ours to configure and yours to inspect.
Learn moreCertifications
Our controls are designed to meet the standards our clients are certified against: ISO 27001 internationally, SOC 2 in the United States. Those frameworks attest to how a vendor secures its own systems that process customer data, and in our delivery model we do not operate such a system. Your data is processed on your enterprise AI platform and inside a cloud you control, under the certifications your platform and your cloud already carry.
The EU AI Act
Its transparency duties apply since August 2026. Our setup already works the way the Act reads: agents are disclosed as agents, sensitive steps wait for human approval, and the audit trail keeps the record your compliance team will ask for. Obligations for the models themselves sit with your AI platform.
The GDPR
In product operation, Supernomial does not process your personal data, and no new subprocessor joins your vendor list. Implementation and support run under your engagement terms.
The controls on your data are your platform’s. Check them at the source.
For your security review
The short answers to the standard vendor questions. Send this page to the people who ask them.
Where data lives
- Your files stay in your workspace
- Warehouse figures sit in your own cloud instance
- Deployed in the region you choose
- In product operation, nothing lands on Supernomial systems
What moves, where
- Model traffic goes to your AI platform, under your agreement
- Read-only access to public reference content
- Web research only when a user asks for it
Access and keys
- No Supernomial account or API key in the products
- Sign-ins to your tools stay in your own browser
- Warehouse access is managed inside your deployment
GDPR position
- In product operation we do not process your data
- No new subprocessor is added to your vendor list
- Engagement work runs under the engagement’s terms