motherAi
CZ · EN
← Back to home

MotherAI Workspace security and architecture

What is controlled, how data flows and what must be confirmed for your deployment. A technical evaluation guide, not a certification.

Updated: 2026-09-10 · MotherAI

  1. Approved channel and identity
  2. Access, model and location rules
  3. Permitted sources and processing
  4. Approval before designated actions
  5. Result and agreed records

How data flows

A request enters through an approved interface. MotherAI applies the user identity and rules for the task, client and sources. Permitted material can go to an approved model in the designated environment. Selected next actions wait for human approval. Results return through an approved channel and agreed records are retained. The exact topology depends on deployment.

LOCAL ONLY covers the task, not just the model

Processing is restricted to the designated local environment. Review document retrieval, OCR, indexes, connected tools, logs and backups as well as inference. Sending a sensitive request through a cloud communication channel makes that part of the path non-local. A requirement to keep everything inside the organisation must therefore define the permitted input channel too.

EU CLOUD, APPROVED CLOUD and ANY

EU CLOUD means an approved cloud environment in the EU, not automatic legal compliance. APPROVED CLOUD restricts processing to named providers. ANY removes the location restriction for that task, not access, action or approval rules. Environment changes must follow policy; silent fallback to another provider must not be assumed.

Permissions and client separation

Configuration determines who can start a task and which client sources they can access. A shared model-provider account does not give everyone shared data permissions. Deployment must verify identity mapping from connected channels and the scope of integration-account permissions. Tools outside the governed MotherAI path are not covered by these controls.

Approval before action

Separate drafting from sending or writing. A rule can allow, block or refer a step to an assigned person. Define the approver, the information they need and what happens if they are unavailable. Verify that the next action does not run without required approval. Approval alone does not replace factual review.

Records and retention

Agree records of sources, models, policies, actions, approvals and results. Retaining full documents differs from retaining execution metadata. Before operation, confirm retention periods, record access, export and deletion including backups. The public offer does not specify one retention period or automatically immutable storage for every deployment.

BYOK and costs

Use company API accounts or your own model infrastructure. MotherAI charges for Workspace and agreed setup; model usage is separate. This is not sharing a personal chat-subscription password. Confirm key storage, permissions, rotation and responsibility for account limits during implementation. Savings depend on usage and subscriptions actually replaced.

Evidence to request during security review

Request the deployment data flow, service list, storage locations, support access, contractual roles and subprocessors. Confirm encryption and key management, backups, incident response and provider terms for retention and use of inputs. This guide does not establish a specific certification, penetration test, SLA or universal provider no-training default.

Verify before production

Run negative tests for another client, an unapproved model, a disallowed environment and an action without approval. Also verify retrieval of an approved result and access to records only by authorised roles. Acceptance criteria and responsibility for repeating tests after integration changes belong in the handover documentation.

Supporting compliance

Access controls, data minimisation, human approval and records support your risk-management process. GDPR also requires an appropriate purpose and legal basis; AI Act duties depend on use and organisational role. Technical controls alone do not establish compliance. The organisation and its advisers must assess the deployment.

Official regulatory sources

European Commission: GDPR principles · EU AI Act

Related guides

AI for law firms: from contract versions to a reviewable draft AI for accounting and audit teams: less document chasing AI for fintechs: prepare client cases under control FAQ

Book a demo for your workflow

Book a demo
Privacy Terms Cookies Cookie settings [email protected]
© 2026 MotherAI