Ask Olive is operated by Olive Wood IT Limited. This page is written for the people who have to sign off a purchase — IT, security, legal and procurement. Where we hold a control today it is described plainly; where a certification is in preparation it is labelled as such and never presented as achieved.
🔒 Security
- Per-customer isolation enforced in the database
- Authenticated sessions, MFA, SSO
- Encryption in transit; edge protection
- Audit logging of project activity
- Cyber Essentials Held
🛡️ Privacy
- UK GDPR; DPA available
- Named sub-processors
- Defined retention & deletion
- Not used to train AI models
🤖 AI governance
- Answers grounded in your authorised knowledge
- Source attribution & refusal when uncertain
- Managed model providers
- Customer knowledge never crosses tenants
⏱️ Availability
- Backups & recovery
- Fails safe if the AI provider is unavailable — no degraded or incorrect answers
- Incident handling & breach notification
Security
Tenant isolation. Every customer's data is separated at the database layer, not just in application code — one customer's content is never retrievable by another, and this separation is enforced by row-level security policies that the application cannot bypass. The application connects with a least-privilege database role for user requests and a separate role for background jobs.
Access control. Access requires an authenticated session. We support multi-factor authentication and trusted-device enrolment, and single sign-on with a work account (Microsoft). Administrative functions are gated separately from ordinary use.
Encryption & boundary. Traffic is encrypted in transit and the service sits behind a protected network edge (access control, TLS termination, request filtering). Databases are not exposed to the public internet.
Access to production data is limited to those who need it to run the service.
Cyber Essentials Held
Ask Olive holds Cyber Essentials certification, covering the five control themes: boundary firewalls, secure configuration, security-update management, user access control and malware protection.
Independent penetration testing
An independent penetration test covering the web application, API, authentication, authorisation, tenant isolation, file uploads and the AI/RAG surface (including prompt-injection and data-leakage tests) is planned. When completed we will state the month and scope here.
Cyber insurance
Cyber-liability and professional-indemnity cover — status to be confirmed.
Privacy
Olive Wood IT Limited is the data controller for the personal data it processes to run the service, and acts as your processor for any personal data you put into the product. Full detail is in the Privacy Notice, which covers what we collect, lawful bases, your rights, and the case where you are the controller.
Customer questions and content are not used to train AI models — neither ours nor any provider's. We do not sell personal data or share it for advertising.
Retention & deletion
Questions and answers, and technical telemetry, are retained for up to 12 months and then automatically deleted by a scheduled job; billing records are kept for 6 years as UK tax law requires. You can ask us to delete your question history sooner. Full table in the Privacy Notice.
Data Processing Agreement
A DPA is available covering controller/processor roles, sub-processors, security, breach notification, deletion, data-subject requests and international transfers. Ask and we will provide a signable copy.
Sub-processors
We use a small number of sub-processors, each contractually bound to protect the data and use it only to provide its service to us.
| Provider | Purpose | Data processed | Location | Trains on your data? |
|---|---|---|---|---|
| Stripe | Payments | Name, email, billing address, card details (supplied directly to Stripe) | USA/Ireland | No |
| Cloudflare | Network protection & delivery | IP address, request metadata | USA/UK | No |
| Microsoft | Sign-in with a work account | Identifier, name, email as released by your organisation | — | No |
We update this register before adding a sub-processor that handles your content. Transfers outside the UK are made under the UK IDTA / SCCs or an equivalent approved mechanism.
AI trust & safety
What Ask Olive does: it answers questions by retrieving your authorised knowledge and reasoning over it with a managed AI model, with source attribution.
What Ask Olive does not do: it does not train foundation models on your data; it does not expose one customer's knowledge to another; and it does not act outside the access you have granted.
Handling uncertainty: answers are grounded in retrieved evidence, cite their sources, and the system is built to say when it does not know rather than guess.
Model management: we use approved model providers, track model versions, and monitor answer quality. Our AI Management System is in place, aligned to ISO/IEC 42001.
Availability
The service is backed up with recovery procedures. Ask Olive relies on a single managed AI provider for inference; if that provider is unavailable, question-answering is temporarily unavailable rather than returning degraded or incorrect answers — the rest of the application (your projects, processes and records) remains accessible. If a breach affects personal data and is likely to be high-risk, we notify the ICO within 72 hours and affected customers without undue delay.
Enterprise security questionnaire
The questions security teams ask most often, answered up front. Hand this section to your IT/security team.
Do you support SSO and MFA?
Where is data stored, and is it encrypted?
Who can access customer data?
Is customer data used to train AI models?
Which AI/LLM providers do you use?
Is data sent outside the UK/EU?
How is tenant isolation implemented?
How long are logs and questions retained?
What happens if your AI provider becomes unavailable?
What happens when a customer terminates, and how quickly can data be deleted?
Do employees have production access, and how is privileged access controlled?
Do you perform penetration testing?
Do you have incident-response procedures?
Reporting a vulnerability
If you believe you have found a security vulnerability in Ask Olive, please report it responsibly to security@owgroup.co.uk. Tell us what you found and how to reproduce it. Please do not access or modify other users' data, degrade the service, or run automated high-volume attacks. We will acknowledge your report within 3 business days and work with you on a fix. Our machine-readable contact is published at /.well-known/security.txt.
Legal documents
| Document | Status | |
|---|---|---|
| Privacy Notice | Published | Read |
| Terms of Service | Published | Read |
| Refund & Cancellation Policy | Published | Read |
| Data Processing Agreement | On request | Contact us |
| Enterprise SLA | On request | Contact us |
Questions a procurement team should feel free to ask: help@owgroup.co.uk. Security reports: security@owgroup.co.uk.