> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tess.im/llms.txt
> Use this file to discover all available pages before exploring further.

# Tess Commitments

The commitments below are not just statements: each one is backed by operational practices, internal policies, and platform capabilities available to the customer.

## Commitments

<AccordionGroup>
  <Accordion title="Confidentiality and integrity">
    **Customer data is protected in transit and at rest.** Access to sensitive information requires authentication and authorization; misuse is limited by access control and segregation between environments and organizations.
  </Accordion>

  <Accordion title="Your content does not train Tess models">
    Prompts, files, memories, and responses generated through platform use are not used to train Tess’s own models. Processing happens to deliver the contracted service, under the privacy notice and terms of use.
  </Accordion>

  <Accordion title="Isolation between organizations">
    Each workspace/organization operates in its own logical boundary. Users from one customer cannot access another customer’s data; roles and permissions limit what each person can see and run inside their own account.
  </Accordion>

  <Accordion title="Traceability of AI executions">
    Relevant interactions are recorded for governance and support — who ran what, in which organizational context, with which models, and with what consumption — enabling audit and investigation when needed.
  </Accordion>

  <Accordion title="Privacy with a dedicated owner">
    We operate under LGPD and practices aligned with GDPR, with a DPO channel for data subjects to exercise rights of access, correction, and deletion, and for privacy questions: [dpo@tess.im](mailto:dpo@tess.im).
  </Accordion>

  <Accordion title="Ongoing transparency">
    Security and compliance practices are communicated through the Trust Center, System Status, and public documentation — for due diligence and day-to-day follow-up.
  </Accordion>
</AccordionGroup>

## Vendors and AI model providers

**Tess is an orchestration layer:** it connects your organization to specialized models and services. That is why third-party risk is treated as a first-class control *(before contracting and throughout the relationship)*.

<CardGroup cols={2}>
  <Card title="Before a critical partner is onboarded">
    * We record who the vendor is, what data they may process, and who owns the relationship inside Tess.
    * We assess security posture — audit reports, questionnaires, or equivalent evidence.
    * When customer data is processed, we require contractual confidentiality and protection obligations.
  </Card>

  <Card title="During day-to-day use">
    * We send model providers only what is needed for the inference the user authorized at that moment.
    * We track contractual data-use restrictions — including no-training commitments when they are part of the agreement.
    * We monitor risk and performance; material vendor changes may require re-assessment.
  </Card>
</CardGroup>

**Typical partner categories:** cloud infrastructure, edge protection and content delivery, identity federation, payment processing, application monitoring, and AI model providers.

## Related

* [Data Protection](/Data-Protection)
* [Privacy](/Privacy)
* [Responsibilities](/Responsibilities)
* [Transparency](/Transparency)
