Client team & advisers
Provide materials, confirm scope, discuss evidence and raise objections. The Sponsor independently decides acceptance.
METHOD & PEOPLE
XYNX organizes methods, tools, professional review and quality control. Clients can inspect scope, evidence and limits while retaining independent decision authority.
01 / CLEAR RESPONSIBILITIES
Provide materials, confirm scope, discuss evidence and raise objections. The Sponsor independently decides acceptance.
Check sources, coverage and omissions within the appointment; make named judgments and verify revisions.
Check the engagement, versions, professional confirmation, open risks and release conditions; issue a traceable delivery version.
These are designed responsibilities. Real practitioners’ identities, credentials, applicable expertise and conflicts require verification before appointment. Demo roles are not actual team members.
02 / INDEPENDENCE IN PRACTICE
Record relationships with the client and supplier and any role in preparing reviewed materials; disclose, mitigate or replace reviewers as necessary.
Compensation is not tied to favorable opinions, finding counts or final acceptance. Adverse recommendations may still satisfy the engagement.
Check support, coverage and omissions and record adoption or rejection. AI-generated lists are not signed opinions.
Clients can challenge opinions with evidence. Rechecks and corrections retain version relationships rather than silently rewriting released opinions.
SECURITY & DATA USE
Project files are stored in Amazon S3, and AI runs on OpenAI API under Zero Data Retention. Storage, AI processing and support access are each disclosed and authorized separately.
Customers choose a storage region at setup: the US by default, with the EU, Japan, Australia and Singapore available on request. Login location never assigns or moves data. Region changes require customer approval, integrity and access checks, a controlled cutover and old-copy cleanup, covering backups, indexes and derived material.
Platform AI and customer connections both run on OpenAI API. AI processing location, international transfers and retention are explained to customers before enablement; local S3 storage does not imply local AI inference.
AI supports Q&A, summaries and translation of authorized material. Web search, external tools and provider-hosted files are enabled only after separate review.
Singapore and Australia operations access only necessary service metadata by default. China development uses only synthetic or de-identified material, with no standing access to customer content.
When troubleshooting requires content access, the staff location, reason, scope and duration must be stated and approved by the customer administrator and an internal authority. Access is logged and expires automatically.
Customer files are stored in Amazon S3 in the chosen AWS region. When AI is used, only the authorized content needed for the request is sent to OpenAI API, and where derived data goes is set out in the terms.
AWS secures its cloud infrastructure; XYNX is responsible for the application, data permissions and configuration, including encryption, public-access blocking, least privilege, logging and recovery.
No. The OpenAI API terms and account configuration we use explicitly exclude customer inputs and outputs from model training, fine-tuning and distillation; we have verified the actual provider, endpoint, account configuration and contract.
Yes. XYNX's OpenAI account is approved and configured for Zero Data Retention (ZDR). The models and features it covers, and any exceptions, are listed in the data terms.
ZDR applies on the model-provider side; XYNX still keeps your project files, audit records and backups as agreed. Customer-owned OpenAI connections are verified separately before enablement.
MFA is mandatory for staff and privileged accounts, and customer user verification follows organization policy. Material access follows roles and current authorization; space membership never grants all-content access or professional signing authority.
Customers needing stronger isolation can choose a dedicated single-tenant environment; the dedicated scope of application, database, object storage, index, log and backup resources is confirmed item by item before setup.
Audit covers sign-in and permission changes, file access and export, AI requests and their authorized material scope, model and processing-policy versions, and support-access approval and revocation, recording who acted, when, why, on which material and with what result.
Audit logs omit file content, full prompts, model credentials and full responses by default, and are protected by access control, retention limits and tamper protection.
We are pursuing ISO/IEC 27001 certification, a SOC 2 Type II audit and GDPR certification on one security and privacy control framework. Once obtained, we will publish the scope, validity or audit period, and how to verify them.
This depends on the data, your contracts and applicable law. International processing of personal data from Europe, Japan and other regions requires the relevant agreements, assessments and safeguards.
If your program requires storage in the EU, Japan, Australia or Singapore, choose that region at setup; for other regional requirements, contact us before uploading materials.
Team members, external collaborators and appointed professionals can use only currently authorized file versions. Sharing, retrieval, AI answers and derived content stay within that scope; revoked permissions cannot be reused.
A workspace seat never grants professional review or release authority automatically. Formal delivery, Source acceptance and Program Memory publication each need separate approval.
Bring-your-own connections currently support only OpenAI API, and the account and endpoint's data-use and retention terms are checked before enablement. The platform account's ZDR arrangement does not automatically extend to your own account.
Before live use, we provide a data-processing agreement covering storage and processing regions, model and other processing providers, access responsibilities, retention and deletion periods including backups, and incident response, with security-control documentation on request.
If your program has specific compliance requirements, raise them before submitting materials and we will confirm the applicable scope and validation approach.
CONTINUE THE CONVERSATION
Explore services and sample deliveries, then try scope questions in the synthetic workspace.
Product workflow demonstration only; no real inquiry or message is sent.