Questions
The sixteen questions that come up before anybody looks at a demo.
Collected from first calls and from security reviews, and answered here so the call can start further along. Each answer is written to stand on its own, so quoting one somewhere else does not strip the qualification off it. Where the honest answer is "not yet", it says that.
What it is
The shape of the thing.
What is Proceptio.AI?
Proceptio.AI is a governed access layer between AI assistants and business systems. It lets a named person ask a question in the assistant they already use, decides whether that person may reach that system with that tool, reads live from the system if so, and writes a record either way. It holds the decision and the record; it holds none of your data. The full list of tools is published.
Do our people have to change assistant?
No. The connector speaks the Model Context Protocol, an open specification several assistant vendors implement, so it is not built around one of them. Claude is the assistant Proceptio.AI has been verified against. Others are supported by the protocol and verified with you during onboarding, which is a named step rather than a promise.
Do you run an AI model?
No. Proceptio.AI runs no model of its own and sells no inference, so your assistant contract stays yours and so does the bill for it. This matters commercially as well as technically: switching assistants leaves your grants, your permission gates, your written rules and your audit trail untouched, because all of them live in this layer rather than in the assistant.
Do we need to understand MCP to buy this?
No. MCP is the open standard that lets an assistant call tools inside your systems, and it is worth ten minutes if you are technical. What matters commercially is that it is an open specification rather than one vendor's interface, so the connector is not a bet on a single assistant. There is a plain explanation on what MCP is.
Data and security
The four a reviewer opens with.
Where does our data go?
Reads happen against your own system, with your own credential, at the moment somebody asks. Nothing is copied or indexed in advance, so there is no second store to secure, to re-permission or to go stale. The figures travel from your system to the assistant your person is using; the only thing kept here is the record that the call happened.
Whose permissions actually apply?
It depends on the system, and Proceptio.AI publishes which is which rather than claiming one answer. Some systems can be read as the signed-in person and enforce that person's own permissions. Others cannot, and then this platform's grants and tool governance are the only access control, with nothing behind them. The per-system table is on whose permissions apply.
Can the assistant change anything?
No. Writing back is disabled in every environment, for every person, and there is no setting that turns it on. A write path exists and is proven in a sibling system, so it can be ported when a client needs it, but that would be a deliberate per-environment decision rather than a flag. Today the accurate description is that this reads and does not write.
Are you SOC 2 certified?
No, and Proceptio.AI does not display badges it has not earned. There has been no external penetration test; the isolation reviews run so far have been internal, though they are documented and each one has found something. What can be shown is the security model itself, including the parts not yet proven, on the security model.
Control and the record
What happens when the answer is no.
What does a refusal look like to the person?
They are told which tool was refused, which permission they do not hold, and who at your company can change it. They are not told what the answer would have been, whether the data exists, or anything about another client. A refusal is a normal readable event rather than an error, because a person who cannot tell "refused" from "broken" raises a ticket for both.
What is in the audit trail?
Every call, allowed or refused, with the person, the tool, the project, the outcome and the reason as a named code rather than a log line. Twenty reason codes exist and a test freezes them, because this is data somebody reads in three years. What a row deliberately does not contain is the figures that came back. See the audit trail.
How fast is revocation?
Removing somebody's grant takes effect on their next call. There is no standing access, no cached permission and no token that keeps working until it expires, because permission is resolved per request rather than issued in advance. This is the direct benefit of keeping identity and permission separate: the assistant never holds an entitlement it can outlive.
Could one client ever read another's data?
That is the failure this platform is built to make structurally impossible rather than unlikely, and it is where its engineering has gone. A request reaches exactly the one project the caller holds a live grant on, every unknown fails closed, and a customer organization cannot cross to another organization at all. The rules and the open items are on the security model.
Getting started
Time, effort and money.
Which systems can it connect to?
Twenty-six systems are modelled across planning, CRM, tasks, documents, finance and service desks. Four have working adapters today: a planning model over SQL, HubSpot, SharePoint and ClickUp. The whole catalogue is published, including the twenty-two that are not built, on connected systems.
How long does it take to start?
The engineering is about a day once consents are in place: one system, a few people, their grants and the audit trail. What actually sets the date is your security review and whatever consent your directory requires for a third-party application, neither of which we control. Both are worth starting first. See what it takes.
What do you need from our IT?
A work-account sign-in test against your directory early, because that is the long pole and it is better discovered in week one. Then a credential for the system being connected, held in a vault, and one person named as the administrator who grants access. No agent is installed on your network and no inbound firewall change is required. The whole list is on what your IT team has to do.
What does it cost?
There is no published price list, and quoting a number here that did not survive contact with your estate would waste both our time. What moves it is how many systems are connected, how many people hold grants, and whether an adapter has to be built. The first conversation is free and the security review pack costs nothing to read.
If your question is not here, it is probably a good one.
The ones that turn into changes usually come from a security reviewer rather than from a buyer. Send it and we will answer it directly, including when the answer is that we have not built it.