Security

Disecta Decision is a controlled layer between the AI and your information. It is delivered as a cloud service built on Microsoft Azure, with identity management, access control, encryption, logging and separation of customer data.

The six controls

Access control

The AI only sees information the user has the right to see.

Access is controlled through single sign-on (SSO), user identity and role-based permissions. Every question is tied to the person who asks it, and their role decides what information the AI can use.

Tool control

The AI can only use the tools and permissions you have defined.

The model has no direct access to your organisation's systems or data. All access goes through defined interfaces and tools, so the AI can only do what those tools allow.

Traceability

Every result traces back to the data, documents and analyses behind it.

Usage, calls, sources and results can all be followed up afterwards. You can see what was asked, which tools were called, which sources were used and what came back.

Exact calculations

Calculations and business logic run in defined functions, not in the language model.

The language model's job is to understand the question and choose the right function. The numbers come from the function itself, so the same input gives the same result every time.

Validation

Results are checked against your data, rules and criteria.

The check runs automatically, as part of every analysis, so no one has to remember to do it. A result that doesn't match your data, rules or criteria is caught before it becomes a decision basis.

Human approval

Disecta Decision only acts in a system you have connected for it, and you choose which actions need a person's approval first.

Disecta Decision suggests, but a person decides. You choose which actions need sign-off, and none of them goes ahead until someone has approved it.

How Disecta Decision differs

Knows your business

Understands your context, uses structured data, searches your documents and retrieves information from your systems.

Works by your rules

Uses defined tools, applies business rules and makes exact calculations.

Shows its work

Runs the analysis, verifies the result and builds a decision basis you can check.

Infrastructure and data protection

Sign-in and access

Access to systems and data follows the principle of least privilege: users and administrators get only the access their work requires.

Sign-in goes through Microsoft Entra ID (formerly Azure Active Directory), with multi-factor authentication (MFA) and role-based access control (RBAC).

Encryption

Data is protected both in transit (TLS 1.2 or later) and at rest. Microsoft Azure encrypts stored data as standard.

Logging

System events and access are logged for troubleshooting, security follow-up, incident handling and audit trails. Logging uses Microsoft's built-in security and monitoring functions.

Where your data is stored

All data stored in Disecta Decision is stored in Sweden. The primary region is Microsoft Azure Sweden Central, with the data centre in Gävle. All application data, databases and the main system storage are handled in this region.

One exception: some supporting services for maps and geodata can be processed in Microsoft's European regions North Europe (Ireland) and West Europe (the Netherlands).

No data is stored outside the EU/EEA, unless that is specifically agreed or a specific function requires it.

Maps and address lookup

Both are optional. Microsoft's map service is used when data in Disecta Decision has coordinates. Only the coordinates and the object names you choose yourself are sent to the service, such as "Facility 1" or "Electricity meter 2". Microsoft stores no data in the service, but information can appear temporarily in Microsoft's technical logs.

The address lookup agent fetches coordinates from address details. When it is used, the address details are sent to Microsoft's European regions for geocoding. They are not stored permanently, but can appear temporarily in Microsoft's technical logs.

Roles under GDPR

In a project, the customer is normally the data controller and Disecta the data processor. Disecta processes personal data only on the customer's instructions and within the purpose of the project.

Sub-processors

Disecta uses established cloud providers for operations and infrastructure, primarily Microsoft Azure. Here Microsoft acts as sub-processor and infrastructure provider.

Incident handling

Disecta works by established routines for identifying incidents, assessing risk, taking action and communicating with the customer if a security incident occurs. Personal data incidents are handled according to GDPR's requirements for reporting and documentation.

Backup and availability

Backup and redundancy are handled through Microsoft Azure's built-in functions for backup, geographic redundancy, restore and high availability.

AI models

AI functions run through Microsoft's Azure OpenAI Service. Disecta doesn't use customer data to train public AI models.

Frequently asked questions

How is this different from ChatGPT or Microsoft Copilot?

Those are general assistants. Disecta Decision is a controlled layer between the AI and your business: it retrieves the right information, uses only defined tools, makes exact calculations in defined functions, and every result can be traced back to its source.

Does the AI make decisions for us?

No. Disecta Decision analyses and suggests. A person reviews and decides, and critical actions can require approval.

Can the AI see everything in our systems?

No. It only sees what the user asking has the right to see, and it can only use the tools and permissions you have defined.

Where is our data stored?

In Sweden. All data stored in Disecta Decision is stored in the Microsoft Azure region Sweden Central, with the data centre in Gävle. Some supporting services for maps and geodata can be processed in Microsoft's European regions in Ireland and the Netherlands.

Which AI models do you use?

AI functions run through Microsoft's Azure OpenAI Service. Disecta doesn't use customer data to train public AI models.

Contact

For questions about security, GDPR or technical architecture, write to Ludvig Lindqvist, CEO: ludvig.lindqvist@disecta.com