LEGAL — TRUST CENTER

Security, data sovereignty, and governance at 9xAI.

How 9xAI approaches data handling, deployment security, and accountability — in plain terms, not just a compliance checklist.

Data sovereignty, as a real choice

Where your data goes shouldn't be an afterthought. 9xAI supports five deployment models — public cloud, private cloud, on-premise, sovereign, and fully air-gapped — so an organization can choose the option that actually matches its requirements, rather than accepting a single default.

For sovereign deployment specifically, workloads can be routed entirely through India-based infrastructure, meaning the data involved in a request doesn't leave the country as part of processing it. This is a genuine deployment option, not a marketing label layered on top of a system built around a different assumption.

Governance and access control

Role-based access

Access to copilots, data, and administrative functions is controlled by role, so people see and do only what their role requires.

Auditability

AI actions taken on the platform can be tracked and reviewed after the fact — useful for compliance-sensitive workflows in regulated industries.

Human-in-the-loop

For decisions that require accountability, the platform is built to keep a human in the loop rather than fully automating consequential actions.

Model independence

No single AI vendor is a structural dependency — routing decisions are made per task, reducing exposure to any one model provider's outages, pricing changes, or policy shifts.

How your data is used

Documents, images, and audio you submit are processed to deliver the response or output you requested. They are not used to train models shared across other customers. Credit-metered features (Document AI, Voice, Dubbing) route through the specific third-party providers required to deliver that feature, under the deployment model your account uses.

Where we are honest about being early

9xAI is a new platform, and we'd rather say so plainly than overstate our current position. Formal third-party security certifications (such as SOC 2 or ISO 27001) are not yet in place for 9xAI specifically — a certification process is a genuine undertaking, and we're not going to claim one prematurely. Twor Consulting Engineers, the company behind 9xAI, holds ISO 9001 quality management certification, but this is a distinct standard from information-security certifications and shouldn't be read as equivalent.

If your organization has specific compliance requirements before adopting 9xAI — a particular certification, a data processing agreement, or a security questionnaire — reach out through the Contact page and we'll work through it directly rather than pointing you at a page that doesn't yet have the answer.

Questions or concerns

For anything not covered here — a specific security question, a request for documentation, or a concern about how your data is being handled — the Contact page reaches our team directly.