Compliance, built in.
Every action is traceable, and nothing sensitive happens without approval. This page shows how, written for your IT team and your data protection officer.
Every action, on the record.
Every case number links to the complete chain of events: arrival, screening, model call, approval, outcome. When you need to know what happened, you pull the audit trail.
- Records can be added, never changed or deleted; the database itself enforces it
- The audit trail holds metadata and summaries, not your documents themselves
- The one exception: redaction after a GDPR erasure request (see "Delete the data, keep the proof")
- ✓AddAllowed. That's how the trail is written.
- ✕EditRejected by the database.
- ✕DeleteRejected by the database.
The order confirmation doesn't match the framework agreement (€4.20 instead of €3.85). I've drafted a query. Send it?
Nothing goes out without your approval.
It works like dual sign-off in your accounting: sending, posting, and changing are locked until a person approves that specific action. Not a company policy, a system rule.
- One approval covers exactly one case, never a batch
- The agent can only use tools you've enabled
- Every approval is on record: who, when, for what
Delete the data, keep the proof
Two duties that contradict each other: the GDPR says delete. Your record-keeping obligations say prove. Most systems can do one or the other. fluado resolves it in the data model: content is redacted, the chain of events stays intact.
- Access, erasure, restriction, objection (Articles 15, 17, 18 and 21 GDPR) are built into the product, not handled through support tickets
- What happened, who approved it, and when: that stays provable
- time
- 08:41:07
- action
- Email sent
- content
- "Price deviation query to k.hoffmann@…"
- approval
- M. Berger
- case
- 7f3a…c2
- time
- 08:41:07
- action
- Email sent
- content
- [REDACTED_DSAR]
- approval
- M. Berger
- case
- 7f3a…c2
- Manipulation attemptsPrompt injection scanning, six attack categories, Unicode-normalized
- CredentialsEntropy scanning catches keys and passwords in output
- Web accessInternal networks blocked, domains restricted by allowlist
- Runaway behaviorA loop guard stops the agent automatically
Screened coming in, screened going out.
Every incoming message is screened before the agent processes it, and every outgoing one before it leaves the building.
- Every screening result lands in the audit trail
- Costs are capped too: daily and monthly budgets, enforced by the system
Your auditor asks. You click.
An audit or a customer question: "Who approved this email, and why was the price queried?" Here's what the answer looks like: one case, followed from arrival to dispatch. The same applies to every tool fluado runs for you.
An order confirmation arrives
The message is screened for anomalies before the agent reads a word of it, automatically, on arrival.
The agent checks it against the framework agreement
The unit price is off: €4.20 instead of €3.85. The agent pulls up the contract before it suggests anything.
A draft, and nothing more
The agent writes a query. Sending is locked without approval, so the draft waits for a human.
The answer to the auditor's question
Approved by M. Berger at 08:41. Reason: deviation from the framework agreement. The whole chain sits under one case number.
What your DPO will want to know.
No. Sending is blocked by policy. Until someone approves that specific case, the draft just sits there.
No. Entries can only be added. The one exception is content redaction after a GDPR erasure request; structure, timestamps and approvals stay in place.
The content is deleted and the summaries in the audit trail are redacted. Deadlines are set in the data processing agreement.
A mistake stays a draft: anything prepared incorrectly is discarded at approval instead of being sent. And since every step is on record, you can see exactly how it happened. If something serious does occur, the contract requires us to notify you within 24 hours.
Incoming messages are screened for manipulation patterns before processing. No filter catches everything, which is why security doesn't rest on the filter: even a compromised agent can't execute anything without approval, and the attempt itself goes on record.
The two core duties of the AI Act come standard: a human approves every sensitive action, and every case is recorded. Which obligations apply to you depends on how you use it.
In the EU, and never used for training. fluado rejects non-EU endpoints in code; the attempt would show up in the audit trail. Our full list of processors is public. List of processors
At the database level: every row carries a tenant ID, and the database enforces the separation on every query (row-level security).
Your IT team has questions?
Good. Twenty minutes, straight with the founders. Bring your DPO.
Or call us: +49 176 2330 6503