Evaluated on your terms. Scoped, reviewable, and reversible.
Decidian is designed to be evaluated without forcing a system replacement. Data handling, access, retention, and governance are documented with the client before any work begins — and every conclusion is traceable to the evidence behind it.
This page is maintained by Decidian to answer common security, privacy, and governance questions. It describes practices and platform behavior, and is not an independent certification or a guarantee of any specific outcome.
Governance is a joint effort between Decidian and the client.
Decidian is responsible for how the platform processes data within the agreed scope. The client is responsible for the data it provides, the decisions it makes with the outputs, and internal approvals. Decidian supports human decision-making; it does not remove executive accountability.
Access is scoped, agreed, and minimized.
Decidian only receives access to the data required for the agreed pilot scope. Access boundaries are documented with the client before work begins.
Only the systems, datasets, and documents needed for the defined decision area are in scope.
Access method — read-only exports, secure share, or a client-provisioned environment — is agreed in writing before the pilot starts.
We request the narrowest access consistent with the pilot's success criteria and remove access when the engagement ends.
Access is granted to named team members, not shared accounts.
Handled inside the boundaries the client sets.
Data is processed within the environment and controls agreed with the client. Specific handling requirements are documented alongside the pilot's scope and access model.
Storage location, transit protection, and processing boundaries are captured in the pilot's engagement documentation.
Client data and derived work products are kept logically separated across engagements.
Client data is not used to train third-party or general-purpose models without written client consent.
Any third-party services that would touch client data are disclosed and require client agreement before use.
Retained only as long as the engagement requires.
Retention windows and deletion procedures are agreed with the client and confirmed at engagement close.
Working data is retained for the duration of the pilot and any agreed post-engagement review window.
At the end of the retention window, data is deleted or returned per the client's instruction and a written confirmation is provided.
Reviewable decision outputs and reports remain with the client; Decidian retains only what the engagement documentation permits.
Who can see what is defined before work begins.
Roles and permissions on both sides are agreed and reviewed with the client.
The Decidian team members with access, and their responsibilities, are named in the engagement documentation.
The client identifies who authorizes access, reviews outputs, and signs off at engagement close.
Any expansion of scope, access, or roles requires written client approval.
Every conclusion traces back to the evidence.
Decidian is built to produce reviewable, traceable decision intelligence — not opaque recommendations.
Conclusions surface the specific documents, records, or signals that support them, along with what is missing or contradictory.
Outputs are structured so client reviewers can inspect the basis for each recommendation.
Scope, access decisions, deliverables, and sign-offs are documented across the engagement lifecycle.
Decidian supports human decision-making — it does not replace it.
Outputs are decision support. Executive accountability for the underlying decision stays with the client.
Every material output is designed to be reviewed by a qualified person on the client side before it informs action.
Outputs are not legal, tax, accounting, medical, regulatory, or investment advice. Material decisions should involve qualified professionals.
Confidence indicators, evidence gaps, and contradictions are surfaced so reviewers can weigh them, not hide them.
The client controls scope, access, and exit.
Clients can adjust the boundaries of the engagement at any time; changes are documented before they take effect.
Any change to data sources, systems, or the decision area under review is confirmed with the client in writing.
The client can pause or end the engagement; access is revoked and data handled per the agreed exit procedure.
Deliverables are provided in formats the client can retain, review, and share internally.
Evaluated on the client's terms, not ours.
Pilots are structured so procurement, security, and governance teams can evaluate Decidian without a system replacement.
Security, privacy, and governance requirements are documented with the client before the pilot begins.
Decidian responds to the client's security questionnaires and vendor-review processes as part of onboarding.
A written trust package — covering data handling, access, subprocessors, retention, and incident contact — is available on request under NDA.
A single point of contact is provided for security questions and, if needed, incident notification during the engagement.
Request the written trust package.
Available under NDA. Covers data handling, access model, subprocessors, retention, deletion, and the named security contact for the engagement. Suitable for procurement, security, and governance review.
Start with one decision that matters.
A focused 15–30 day pilot, scoped and governed on your terms.
