Commitments
Confidentiality and integrity
Confidentiality and integrity
Customer data is protected in transit and at rest. Access to sensitive information requires authentication and authorization; misuse is limited by access control and segregation between environments and organizations.
Your content does not train Tess models
Your content does not train Tess models
Prompts, files, memories, and responses generated through platform use are not used to train Tess’s own models. Processing happens to deliver the contracted service, under the privacy notice and terms of use.
Isolation between organizations
Isolation between organizations
Each workspace/organization operates in its own logical boundary. Users from one customer cannot access another customer’s data; roles and permissions limit what each person can see and run inside their own account.
Traceability of AI executions
Traceability of AI executions
Relevant interactions are recorded for governance and support — who ran what, in which organizational context, with which models, and with what consumption — enabling audit and investigation when needed.
Privacy with a dedicated owner
Privacy with a dedicated owner
We operate under LGPD and practices aligned with GDPR, with a DPO channel for data subjects to exercise rights of access, correction, and deletion, and for privacy questions: dpo@tess.im.
Ongoing transparency
Ongoing transparency
Security and compliance practices are communicated through the Trust Center, System Status, and public documentation — for due diligence and day-to-day follow-up.
Vendors and AI model providers
Tess is an orchestration layer: it connects your organization to specialized models and services. That is why third-party risk is treated as a first-class control (before contracting and throughout the relationship).Before a critical partner is onboarded
- We record who the vendor is, what data they may process, and who owns the relationship inside Tess.
- We assess security posture — audit reports, questionnaires, or equivalent evidence.
- When customer data is processed, we require contractual confidentiality and protection obligations.
During day-to-day use
- We send model providers only what is needed for the inference the user authorized at that moment.
- We track contractual data-use restrictions — including no-training commitments when they are part of the agreement.
- We monitor risk and performance; material vendor changes may require re-assessment.

