Security & Trust
Built to pass your security review.
We work inside your environment and your jurisdiction, under your controls, with a named person accountable for every change an agent makes. Here is how, and what your risk team can ask us for.
Six commitments we put in the contract.
Your environment, your country
We build in your cloud accounts, repositories and pipelines, under your identity provider and access policies. Clients outside India run our products on their own databases and architecture, in their own country, so data never has to leave it.
Your data never trains a model
Not ours, not a provider's. We use models through your own accounts, on commercial terms that forbid training, or as open-weight models inside your network.
People approve, agents assist
Agents propose; named engineers review and approve. Human approval gates sit in front of anything that changes code, data or a live system.
Every action is traceable
Agent actions and approvals are logged. Code an agent writes goes through the same pull-request review, tests and CI checks as code a person writes.
Any model your rules allow
Frontier models through your cloud provider, or open-weight models on your own infrastructure. The Workbench runs on AWS Kiro, Claude Code or OpenCode, so you are not tied to one vendor.
You own what we build
By default, source, documentation and runbooks are handed over, and your team is trained to run and extend the system after we step back.
How an engagement is secured.
The same controls, from the first call to the day we step back.
01 / Before we start
- NDA signed before any data is shared
- Data processing agreement in place, and your security questionnaire answered
- A named team, with each person’s access approved by you
- Agreed data classes: what agents may see, and what they never see
02 / While we build
- Least-privilege access through your SSO, with MFA
- Masked or synthetic data in development; production data only with your written approval
- Secrets kept out of prompts, logs and repositories
- A weekly review with your team: the demo, the metric and the open risks
03 / When we hand over
- All WeXL access revoked and the credentials we used rotated
- Your data returned or deleted, confirmed in writing
- Runbooks, evals and observability in place
- Your team trained to run it without us
Controls built for agents at work.
Agents move fast. These controls, part of Forge, make sure quality and accountability keep up.
- SteeringYour rules, encoded
- Your architecture rules, coding standards and definitions of done are written into the Workbench, so every agent follows them.
- GuardPolicy checks and approval gates
- What each agent may do is set by policy, every action is recorded, and sensitive steps wait for a named person to approve.
- ReviewEvery change reviewed
- Each pull request is checked against your standards before a person approves the merge.
- EvalsQuality you can measure
- Accuracy, drift and cost of every agent in production are tracked and reported, with alerts when they move.
The rules you work under.
Your obligations stay yours. Our job is to make the evidence easy to produce. We map our delivery controls to the frameworks you report against, and document them for your auditors.
- India DPDP Act, 2023
- RBI IT governance and outsourcing directions
- MAS Technology Risk Management Guidelines
- EU and UK GDPR
- EU AI Act
- ISO/IEC 42001
- NIST AI RMF
Who you contract with.
WeXL AI is the operating brand of WeXL Edu Limited, a public limited company incorporated in India. Every contract and invoice is issued by WeXL Edu Limited.
- Legal entity
- WeXL Edu Limited
- CIN
- U85499TG2020PLC142487
- GSTIN
- 36AACCW7031Q1ZT
- Signing authority
- Executive Directors only, as authorised by the Board. Anyone else needs their written authorisation.
For your risk team
Request our security pack.
Everything your security, risk and procurement teams need for vendor due diligence, shared under NDA and sent within two working days.
- Security overview: how we secure our people, devices, access and data
- Engagement architecture and data-flow diagram, including where models run
- AI governance approach: approval gates, audit trail and evals
- Our answers to your security questionnaire (SIG Lite, CAIQ or your own)
- Standard NDA and data processing agreement
Found a vulnerability?
Write to info@wexledu.com with enough detail for us to reproduce it. We will not take legal action against anyone who reports in good faith. See our terms of use for the details.
Start here