Ask Olive is operated by Olive Wood IT Limited. This page is written for the people who have to sign off a purchase — IT, security, legal and procurement. Where we hold a control today it is described plainly; where a certification is in preparation it is labelled as such and never presented as achieved.

🔒 Security

  • Per-customer isolation enforced in the database
  • Authenticated sessions, MFA, SSO
  • Encryption in transit; edge protection
  • Audit logging of project activity
  • Cyber Essentials Held

🛡️ Privacy

  • UK GDPR; DPA available
  • Named sub-processors
  • Defined retention & deletion
  • Not used to train AI models

🤖 AI governance

  • Answers grounded in your authorised knowledge
  • Source attribution & refusal when uncertain
  • Managed model providers
  • Customer knowledge never crosses tenants

⏱️ Availability

  • Backups & recovery
  • Fails safe if the AI provider is unavailable — no degraded or incorrect answers
  • Incident handling & breach notification

Security

Tenant isolation. Every customer's data is separated at the database layer, not just in application code — one customer's content is never retrievable by another, and this separation is enforced by row-level security policies that the application cannot bypass. The application connects with a least-privilege database role for user requests and a separate role for background jobs.

Access control. Access requires an authenticated session. We support multi-factor authentication and trusted-device enrolment, and single sign-on with a work account (Microsoft). Administrative functions are gated separately from ordinary use.

Encryption & boundary. Traffic is encrypted in transit and the service sits behind a protected network edge (access control, TLS termination, request filtering). Databases are not exposed to the public internet.

Access to production data is limited to those who need it to run the service.

Cyber Essentials Held

Ask Olive holds Cyber Essentials certification, covering the five control themes: boundary firewalls, secure configuration, security-update management, user access control and malware protection.

Independent penetration testing

An independent penetration test covering the web application, API, authentication, authorisation, tenant isolation, file uploads and the AI/RAG surface (including prompt-injection and data-leakage tests) is planned. When completed we will state the month and scope here.

Cyber insurance

Cyber-liability and professional-indemnity cover — status to be confirmed.

Privacy

Olive Wood IT Limited is the data controller for the personal data it processes to run the service, and acts as your processor for any personal data you put into the product. Full detail is in the Privacy Notice, which covers what we collect, lawful bases, your rights, and the case where you are the controller.

Customer questions and content are not used to train AI models — neither ours nor any provider's. We do not sell personal data or share it for advertising.

Retention & deletion

Questions and answers, and technical telemetry, are retained for up to 12 months and then automatically deleted by a scheduled job; billing records are kept for 6 years as UK tax law requires. You can ask us to delete your question history sooner. Full table in the Privacy Notice.

Data Processing Agreement

A DPA is available covering controller/processor roles, sub-processors, security, breach notification, deletion, data-subject requests and international transfers. Ask and we will provide a signable copy.

Sub-processors

We use a small number of sub-processors, each contractually bound to protect the data and use it only to provide its service to us.

ProviderPurposeData processedLocationTrains on your data?
StripePaymentsName, email, billing address, card details (supplied directly to Stripe)USA/IrelandNo
CloudflareNetwork protection & deliveryIP address, request metadataUSA/UKNo
MicrosoftSign-in with a work accountIdentifier, name, email as released by your organisation—No

We update this register before adding a sub-processor that handles your content. Transfers outside the UK are made under the UK IDTA / SCCs or an equivalent approved mechanism.

AI trust & safety

What Ask Olive does: it answers questions by retrieving your authorised knowledge and reasoning over it with a managed AI model, with source attribution.

What Ask Olive does not do: it does not train foundation models on your data; it does not expose one customer's knowledge to another; and it does not act outside the access you have granted.

Handling uncertainty: answers are grounded in retrieved evidence, cite their sources, and the system is built to say when it does not know rather than guess.

Model management: we use approved model providers, track model versions, and monitor answer quality. Our AI Management System is in place, aligned to ISO/IEC 42001.

Availability

The service is backed up with recovery procedures. Ask Olive relies on a single managed AI provider for inference; if that provider is unavailable, question-answering is temporarily unavailable rather than returning degraded or incorrect answers — the rest of the application (your projects, processes and records) remains accessible. If a breach affects personal data and is likely to be high-risk, we notify the ICO within 72 hours and affected customers without undue delay.

Enterprise security questionnaire

The questions security teams ask most often, answered up front. Hand this section to your IT/security team.

Do you support SSO and MFA?
Yes to both. Single sign-on with a Microsoft work account, and multi-factor authentication (TOTP) available on every account, with trusted-device enrolment.
Where is data stored, and is it encrypted?
The knowledge base, your question history and the billing ledger are held on infrastructure we control in the United Kingdom. Traffic is encrypted in transit.
Who can access customer data?
Access to production data is limited to those who need it to run the service. Between customers, data is isolated at the database layer — one customer's content is never retrievable by another.
Is customer data used to train AI models?
No. Neither ours nor any provider's. Our model provider's commercial terms provide that inputs and outputs are not used to train its models.
Which AI/LLM providers do you use?
A managed AI provider for inference, under commercial terms that your inputs and outputs are not used to train its models.
Is data sent outside the UK/EU?
Questions are sent to our AI provider (USA) to generate answers, and payment data to Stripe. Transfers use the UK IDTA / SCCs or an equivalent mechanism. Those are the only routine routes by which data leaves our systems.
How is tenant isolation implemented?
Row-level security policies in the database enforce that each customer sees only their own data — enforced below the application, so application code cannot bypass it.
How long are logs and questions retained?
Questions, answers and technical telemetry: up to 12 months, then automatically deleted. Billing records: 6 years (UK tax law).
What happens if your AI provider becomes unavailable?
Question-answering pauses until the provider is reachable again — the service fails safe rather than returning degraded or incorrect answers. The rest of the application (your projects, processes and records) stays available throughout.
What happens when a customer terminates, and how quickly can data be deleted?
We delete or return your data when your account ends and the applicable retention periods have run; you can request deletion of question history sooner.
Do employees have production access, and how is privileged access controlled?
Access to production data is limited to those who need it to run the service. A formal privileged-access policy statement is being finalised.
Do you perform penetration testing?
An independent penetration test is planned; the date and scope will be published here on completion.
Do you have incident-response procedures?
Yes, including breach assessment and regulator/customer notification within the timelines UK GDPR requires.

Reporting a vulnerability

If you believe you have found a security vulnerability in Ask Olive, please report it responsibly to security@owgroup.co.uk. Tell us what you found and how to reproduce it. Please do not access or modify other users' data, degrade the service, or run automated high-volume attacks. We will acknowledge your report within 3 business days and work with you on a fix. Our machine-readable contact is published at /.well-known/security.txt.

DocumentStatus
Privacy NoticePublishedRead
Terms of ServicePublishedRead
Refund & Cancellation PolicyPublishedRead
Data Processing AgreementOn requestContact us
Enterprise SLAOn requestContact us

Questions a procurement team should feel free to ask: help@owgroup.co.uk. Security reports: security@owgroup.co.uk.