MotherAI Workspace security and architecture
What is controlled, how data flows and what must be confirmed for your deployment. A technical evaluation guide, not a certification.
Updated: 2026-09-10 · MotherAI
- Approved channel and identity
- Access, model and location rules
- Permitted sources and processing
- Approval before designated actions
- Result and agreed records
How data flows
A request enters through an approved interface. MotherAI applies the user identity and rules for the task, client and sources. Permitted material can go to an approved model in the designated environment. Selected next actions wait for human approval. Results return through an approved channel and agreed records are retained. The exact topology depends on deployment.
LOCAL ONLY covers the task, not just the model
Processing is restricted to the designated local environment. Review document retrieval, OCR, indexes, connected tools, logs and backups as well as inference. Sending a sensitive request through a cloud communication channel makes that part of the path non-local. A requirement to keep everything inside the organisation must therefore define the permitted input channel too.
EU CLOUD, APPROVED CLOUD and ANY
EU CLOUD means an approved cloud environment in the EU, not automatic legal compliance. APPROVED CLOUD restricts processing to named providers. ANY removes the location restriction for that task, not access, action or approval rules. Environment changes must follow policy; silent fallback to another provider must not be assumed.
Permissions and client separation
Configuration determines who can start a task and which client sources they can access. A shared model-provider account does not give everyone shared data permissions. Deployment must verify identity mapping from connected channels and the scope of integration-account permissions. Tools outside the governed MotherAI path are not covered by these controls.
Approval before action
Separate drafting from sending or writing. A rule can allow, block or refer a step to an assigned person. Define the approver, the information they need and what happens if they are unavailable. Verify that the next action does not run without required approval. Approval alone does not replace factual review.
Records and retention
Agree records of sources, models, policies, actions, approvals and results. Retaining full documents differs from retaining execution metadata. Before operation, confirm retention periods, record access, export and deletion including backups. The public offer does not specify one retention period or automatically immutable storage for every deployment.
BYOK and costs
Use company API accounts or your own model infrastructure. MotherAI charges for Workspace and agreed setup; model usage is separate. This is not sharing a personal chat-subscription password. Confirm key storage, permissions, rotation and responsibility for account limits during implementation. Savings depend on usage and subscriptions actually replaced.
Evidence to request during security review
Request the deployment data flow, service list, storage locations, support access, contractual roles and subprocessors. Confirm encryption and key management, backups, incident response and provider terms for retention and use of inputs. This guide does not establish a specific certification, penetration test, SLA or universal provider no-training default.
Verify before production
Run negative tests for another client, an unapproved model, a disallowed environment and an action without approval. Also verify retrieval of an approved result and access to records only by authorised roles. Acceptance criteria and responsibility for repeating tests after integration changes belong in the handover documentation.
Supporting compliance
Access controls, data minimisation, human approval and records support your risk-management process. GDPR also requires an appropriate purpose and legal basis; AI Act duties depend on use and organisational role. Technical controls alone do not establish compliance. The organisation and its advisers must assess the deployment.