Where is the data, where is the code, and where is your advantage?

The second episode of “Four questions before choosing an AI environment” separates the word “security” into three distinct issues: data location, employees’ working materials and ownership of developed processes. Each calls for a different solution, and each carries a different cost if handled incorrectly.
In conversations about AI, “security” usually means three entirely different things that should be separated before a decision is made. An organisation’s most valuable knowledge is often hidden in working materials that employees do not want to send anywhere, while its real advantage lies in process logic that can easily be lost when changing suppliers.
In this episode, we discuss these three issues one by one:
Data location — it is a choice, not a default setting. On-premises, within the EEA or globally, separately for different processes. Applying one level of protection to everything leads either to overpaying or to people bypassing the rules. We also explain a distinction that supplier offers sometimes blur: server location is not the same as the supplier’s jurisdiction.
Working materials — the most difficult case is not the corporate repository, but draft analyses, notes and correspondence stored on an individual specialist’s computer. We demonstrate the local TWIN:DESK agent in practice: the material never leaves the workstation, while the user gets an assistant that understands their work.
Process ownership — when the way a case is handled, the sequence of steps and the decision criteria are stored in someone else’s environment configuration, they are no longer entirely yours. In SAIE, processes are implemented in the client’s environment, and the code and training are transferred. The advantage built through working with AI is therefore not rented — it becomes an asset on the organisation’s balance sheet.
The episode closes with seven questions to ask every supplier, including us. The most revealing is the final one: who is responsible if the system shows an employee a document they are not authorised to access? This situation occurs most often in practice — and it is a security incident, not a defect.
Data, code and processes are three different things. SAIE is designed so that the answer for all three is “with us” — even if you later change your mind about the supplier.
In episode three: compliance as a ready-made recipe rather than a project you have to build.
VIDEO · EPISODE 2
Where are your data, code and organisational advantage?
The second episode in the series about control over data, code and work context
- Episode 1: How much does an AI environment really cost?