Skip to content
Caramel.
← Back to chat

Trust and security

What a compliance officer or a procurement team needs before the first meeting: how we handle data, what we sign, what is certified and what is not yet.

How we handle security and sensitive data

The answers we give in pre-sales, published here word for word.

Sensitive data in AI
With concrete controls: PII and confidential information filters so nothing sensitive leaves the perimeter, the option to deploy models in the client's own environments — on-premise or private cloud — classification by sensitivity, and granular monitoring of what the agents consume and produce. In digital asset solutions, key custody can sit with the client, with us, or in a hybrid arrangement.
NDAs and corporate compliance
Yes. We work regularly with banks and energy companies, where confidentiality, security and compliance are a requirement, and we adapt to each client's procurement, NDAs and audits. Building regulatory compliance matrices is part of what we deliver on projects of that kind.
AI governance
Before scaling we install strategy, measurement and governance: indicators, visibility and cost control, an approved tool set and granular usage monitoring. Adoption is organised into three environments: exploratory with synthetic data, self-managed by the business, and enterprise when criticality, sensitive data or deep integrations are involved. Adopting without measurement ends in cost without return, as happened with the RPA boom.
From pilot to production
Three practices: design starts from business value and integration with existing systems, not from the demo; the same team that designs builds and runs it, so the architecture is thought for production from day one; and operations exist as an explicit service, with support and evolution after go-live.
Results and expectations
We are deliberately honest about expectations: improvement targets are set as hypotheses and the first phase confirms or adjusts them. With generative AI, accuracy improves iteratively and a share of cases always goes to a person, which is why the architecture includes human review from the design stage. Results are measured against objective references agreed with the client.

Technology partners

The platforms we integrate and operate inside regulated environments. What each side brings is on the services page.

  • AWSCloud and data
  • AnthropicModels and agents
  • SalesforceCRM and workflow
  • OneSpanIdentity and signature
See what each partner brings ↗

Accessibility statement

This site is built to WCAG 2.2 level AA. We do not claim full conformance: what follows is what has been verified, and what has not.

Verified

  • Automated audits with axe-core 4.13 and Lighthouse on the home, contact and projects pages, mobile and desktop, on September 17, 2026: no violations, accessibility score 100 on every page audited.
  • On those pages: keyboard navigation of the chat and the contact flow, visible focus, one h1 per page, a label on every form field, text contrast at AA, and a reduced-motion alternative for every animation.

Not yet verified

A manual pass with VoiceOver and NVDA, zoom between 200 and 400 percent, physical mobile keyboards, and the pages not covered by the automated run. Until then this is an accessibility statement, not a conformance certificate or a VPAT.

If something on this site blocks you, write to sales@caramelpoint.com and we fix it.

Security questionnaires and RFPs

We answer vendor security questionnaires, sign NDAs and adapt to each client's procurement and audits. Send yours and we reply with the evidence, not with a brochure.

Send a questionnaire
Back to chat