TTobyAI

Security and privacy

Held in Sydney, kept from AI, never used to train

Payroll, tax positions, the names and bank details of staff. This page says where that data goes, what never reaches an AI, and how each promise is held by code rather than by a policy document.

Where your data is

In Sydney. Compute, the database, the encrypted store for connection tokens and the operational logs all run in the AWS Sydney region. Data is encrypted in transit and at rest. The AI models the hosted assistant uses run in Australia on Amazon Bedrock, so an explanation request does not leave the country either.

The one exception is this public website: Netlify counts page views from its server logs outside Australia. No script, no cookie, no customer data.

What AI sees, and what it never sees

Tax file numbers, bank account numbers, salary figures, employee names and raw organisation identifiers never reach an AI provider.

Every figure TobyAI states is calculated by TobyAI's own software, which contains no AI at all. AI is used afterwards, to explain a computed result or a provision in plain language. Before anything crosses to a model, the record is reduced to the non-personal shape the explanation needs: an account code, a label, a computed figure, a provision reference. Identifiers that must survive the crossing, so an explanation can refer back to a finding, are replaced with a salted hash unique to your organisation, which the model cannot reverse and which means nothing outside your organisation's account.

No training on your data

Nothing you send to TobyAI is used to train a model, ours or anyone else's. The hosted assistant runs on models we call, not models we tune, and the provider terms under which they run in Sydney do not permit training on the requests. Your ledger, your payroll, your questions and the answers you receive are yours; the only thing TobyAI learns from them is what it recorded for your own audit trail.

TobyAI can also remember, per organisation and without personal information, which checks were useful, so the assistant picks up where you left off. An owner can switch it off, which deletes the record.

Who can see what

Sign-in is through a managed identity provider; TobyAI stores no passwords. Each organisation has its own account, and every read and write is scoped to it. Within that account an owner can invite and remove members, connect and disconnect software, manage billing and switch the de-identified record on or off; a member can run the tools and read the results. Every tool call is recorded against the person who made it.

TobyAI staff do not read customer data in the ordinary course. Operational logs record hashed identifiers, not the values behind them. Where support needs to look at a specific record, it is with your permission.

Connected software

A Xero connection is read-only, authorised by you in Xero, and the token is held encrypted in Sydney. TobyAI reads the accounting and payroll data the checks need and writes nothing back to your file. You can revoke the connection in Xero at any time, and it stops that moment. Exports from MYOB, QuickBooks and payroll systems are uploaded by you, read once, and the checks run over them the same way.

How the promises are held

Each promise above corresponds to something in the product.

  • Residency: the infrastructure is defined in code that names the Sydney region, and the assistant's model routing is bound to a register of measured Sydney models.
  • PII boundary: deterministic gates in the build refuse an AI-provider import in the compliance layer and refuse a raw identifier or person's name in model-readable text.
  • Attested figures: every schedule carries its source, its date and a signed fingerprint; the engine refuses a schedule whose fingerprint does not match.
  • Independent review: every change to the code is reviewed by a model from a different family than the one that wrote it before it can merge, and that review is not treated as compliance sign-off.
  • Audit trail: each run records what was asked, the schedule version, the source and the working, so an answer can be reconstructed later.

This page describes the product as it ships today. Where the privacy policy on this site is narrower, that is because it currently covers the waitlist; it is updated as the product reaches general access.

Questions and requests

To access, correct or delete your information, or to ask how any of this works, write to hello@tobyai.io. A person reads it. TobyAI handles personal information in accordance with the Privacy Act 1988 (Cth).

Read the rest

The FAQ covers how TobyAI works beside your software, and pricing is one plan per seat.

Read the FAQ