erp.io
Pricing
Log inBook a demo
HomeTrustAI and your data

Trust

AI and your data

Putting a language model near a general ledger raises reasonable questions. This page answers them specifically: what leaves your tenant, what a provider may do with it, what we do not do, and what an agent is structurally prevented from doing regardless of how it is configured.

Effective
August 18, 2026
Last updated
August 18, 2026
Entity
Nead, LLC (d/b/a DEV.co)

Contents

  1. 01The short version
  2. 02What is actually sent to a model provider
  3. 03What the provider may and may not do
  4. 04What we do and do not do with your data
  5. 05What an agent cannot do
  6. 06What is recorded when an agent acts
  7. 07Accuracy, and what we do not claim
  8. 08Turning it off
  9. 09Questions

Questions about this policy?

Nead, LLC (d/b/a DEV.co)
1425 Broadway 22689
Seattle, WA 98112
United States

[email protected]

01The short version

  • Your data is not used to train models. Not ours, not a provider’s. This is contractual, not a policy statement we could quietly change.
  • Content is sent to a model provider only to produce an output for a feature you have enabled, and only the content that feature needs.
  • Agents cannot release payment, change vendor banking details, grant permissions, close a period, or file anything statutory. These are not configurable.
  • Every automated action is logged with the inputs read, the policy relied on, the confidence assigned, and the alternatives rejected.
  • AI features can be switched off entirely at the tenant level, and the rest of the service keeps working.

02What is actually sent to a model provider

Only the content required for the specific feature you invoked. There is no background process that streams your ledger to a third party.

FeatureWhat is transmitted
Bill codingThe invoice document text, the vendor record, prior coding history for that vendor, and the relevant portion of the chart of accounts
MatchingThe candidate records being compared and the fields relevant to the comparison
Copilot queriesYour question, and the query results the permission model permits you to see
Document extractionThe document being processed
Drafting and commentaryThe figures and context relevant to what is being drafted

What is not transmitted

  • Your full ledger, database, or document archive.
  • Data outside the scope of the actor invoking the feature — the permission model applies before anything is assembled, not after.
  • Data belonging to any other tenant. Prompts are constructed per request from a single tenant’s scoped data.
  • Credentials, API keys, or connection secrets.

03What the provider may and may not do

Our agreements with AI model providers include the following terms:

TermPosition
Training on our contentProhibited. Content submitted through our service may not be used to train or fine-tune models.
RetentionZero or limited retention, solely for abuse monitoring, under the terms of our enterprise agreement.
Human reviewNot permitted for our traffic except where required for a specific abuse investigation.
Onward disclosureProhibited except where legally compelled.
Processing locationUnited States.

The current provider is listed on our subprocessors page, and we give 30 days’ notice before changing it.

04What we do and do not do with your data

We do not

  • train, fine-tune, or distil any model on Customer Data;
  • use one customer’s data to improve outcomes for another;
  • build evaluation sets from customer records;
  • retain prompts or completions beyond what is needed for the audit trail; or
  • allow our engineers routine access to Customer Data.

We do

  • improve agent behaviour through prompts, policies, and evaluation sets built from our own synthetic and internal test data;
  • record every automated action in the audit trail, including reasoning, which is Customer Data and exportable by you;
  • measure accuracy, escalation, and reversal rates per workflow, which produce counts rather than copies of your records; and
  • publish aggregated benchmarks only from customers who have opted in, aggregated so no customer is identifiable, and never from fewer than five contributing customers.

Opting out of benchmark contribution changes nothing about the service you receive. It is not tied to pricing, support, or feature access.

05What an agent cannot do

The most important control is not what an agent is told to do. It is what it is structurally unable to do.

Agents are actors in the same permission and policy model as people, API credentials, and portal users. They hold no elevated credential and have no path to the ledger that bypasses the policy engine. The following actions are unavailable to any agent at any configuration, and we will not enable them on request:

  • releasing a payment;
  • creating a vendor or changing vendor banking details;
  • granting, modifying, or escalating permissions;
  • closing or reopening an accounting period; and
  • making a statutory filing.

This matters for a specific reason. An agent that reads documents can, in principle, be influenced by instructions hidden in a document — a technique known as prompt injection. We assume that will eventually succeed against any model. The defence is therefore not to make the model harder to fool but to keep the worst available outcome boring, and that means bounding authority below the level at which a successful injection would matter.

06What is recorded when an agent acts

When a person codes an invoice, the reasoning lives in their head, and audit practice has always accepted that. When an agent does it there is no head, and a log entry saying an agent set an account is a record of an outcome rather than of a decision.

Every automated action therefore records:

  • the inputs it read, including which documents and records;
  • the policy or authority grant that permitted the action;
  • the calibrated confidence it assigned;
  • the alternatives it considered and why each was rejected; and
  • the resulting change, with before and after values.

Entries are append-only and hash-chained, so alteration or removal is detectable. No actor can edit them, including our own engineers. The trail is Customer Data, is included in every export, and is retained for seven years by default.

07Accuracy, and what we do not claim

We publish measured straight-through rates by workflow, including the interquartile spread. Those figures range from 94% on purchase order matching down to 66% on multi-line allocation, and the bottom quartile of customers sits materially below every median we publish.

Those are historical measurements across our customer base. They are not a warranty and not a prediction about your environment. Accuracy depends substantially on your vendor concentration, document quality, policy clarity, and history depth — four things that are yours rather than ours.

We will run an evaluation against several hundred of your own historical transactions with known outcomes before you commit, and tell you where it fails. That is the only benchmark that predicts your result.

Where an agent’s measured accuracy or calibration deteriorates, its authority is reduced rather than defended. Any release that regresses accuracy or calibration on our evaluation sets does not ship.

08Turning it off

AI features can be disabled at the tenant level. With them off, the ledger, subledgers, reporting, consolidation, integrations, portals, and the audit trail all continue to function. You lose the automation, not the system.

Individual workflows can also be disabled separately, so you can run agents on bill coding while keeping expense coding entirely manual.

To disable AI features, or to discuss a configuration that keeps particular data categories away from model providers, write to [email protected].

09Questions

For our Data Processing Addendum, the relevant provider terms where we are permitted to share them, or answers to a security questionnaire, write to [email protected].

Nead, LLC (d/b/a DEV.co), 1425 Broadway 22689, Seattle, WA 98112, United States.

erp.io

ERP software with AI agents inside it — and the implementation, integration, and custom development that make it fit how you already work. We research and compare the rest of the market too, including the products we compete with.

AI
  • AI agents
  • ERP Copilot
  • Governance
  • Authority levels
  • Accuracy method
  • AI in ERP report
Platform
  • General ledger
  • Shadow ledger
  • Close
  • Reporting
  • Customer portals
  • API & MCP
Services
  • Implementation
  • Implementation rescue
  • Integration
  • Migration
  • Custom modules
  • Pricing
Research
  • ERP directory
  • Comparisons
  • Free tools
  • Guides
  • Glossary
  • Methodology
Company
  • About
  • Editorial policy
  • Partners
  • Trust center
  • Careers
  • Contact
© 2026 erp.io — a product of Nead, LLC (d/b/a DEV.co)We rank competitors honestly. No paid placement, ever.LegalPrivacyTermsDPASLACookiesStatus