Winsen One
SECURITY & DEPLOYMENT

Built for buildings with a compliance floor.

A chatbot that says something wrong is awkward. An AI employee that does something wrong is a finding. So the wrong thing is hard to do, easy to catch, and always attributable to a named approver.

Read the docs
TL;DRWinsen AI employees are permission-aware (they see only what they are granted), approval-first (no output counts until a named human signs it), and fully audited (every action has a receipt). Small teams run on managed SaaS, one shared deployment we operate. Enterprises take the custom grade: on your own infrastructure or a dedicated isolated unit, both single-tenant. Your data is customer-owned and exportable, never mixed with another customer's, and we never train on it.

Permission. Approval. Audit.

The three questions every security team asks, answered by design.

01
Permission-aware

Can it even see that?

An AI employee holds exactly the access you grant it. Nothing more. If your reviewer cannot open a file, neither can the employee working that queue. No new access surface. No data crossing team lines.

  • Access scoped per role, granted by you
  • Source-system permissions always respected
  • No "AI admin" backdoor to your data
02
Approval-first

Should it really do that?

Nothing an AI employee produces counts until a named person approves it. Findings, closures, dispositions: all drafts until sign-off. This is not a setting we added. It is the contract the product is built on.

  • Every output waits for a named approver
  • Every approval logged with its evidence
  • You grant autonomy per action type, and can revoke it
03
Full audit

What exactly did it do?

Every read, every check, every draft, every approval is logged with its reasoning, the data it touched, and the outcome. Built to face internal audit, statutory auditors, and regulators. Not a black box. A glass one.

  • Every action carries its reasoning and evidence
  • Filter by employee, action, or outcome
  • Export on demand for compliance and audit

Deployed where your regulator is comfortable.

Three arrangements, two grades, one product. Managed SaaS for small teams. On your infrastructure and a dedicated isolated unit for enterprises: that is where single-tenant isolation lives. Same employees, same approvals, same audit trail, wherever it runs.

For small teams

Managed SaaS

One shared multi-tenant deployment, run by us end to end. Encrypted, audited, exportable, and your data is never mixed with another customer's. Sign up and go.

Custom grade · inside your perimeter

On your infrastructure

Single-tenant, deployed in your own cloud or data center: your database, your storage, your domain. Documents never leave your perimeter. Winsen operates the runtime. Priced in the contract.

Custom grade · operated by us

Dedicated isolated unit

A single-tenant deployment we host exclusively for you, in your region, on your custom domain. We operate it. Your security team inspects it. Most "it must be in-house" mandates actually need exactly this.

What the audit trail looks like.

One morning of one AI employee's work on one loan file. Every action, its evidence, and the person who signed off. This is what your auditor scrolls through.

Audit trail · Loan file HL-2847Vera · Credit file review
09:41:03READ

Opened loan file HL-2847. 34 documents, scope: credit review.

09:41:27CHECK

Verified stated income against 12 months of bank statements. 2 discrepancies flagged.

09:42:10DRAFT

Exception report drafted with both discrepancies and source pages attached. Waiting for approval.

09:47:52APPROVED

Signed off by R. Mehta, Senior Credit Officer. Report released to the file.

Every row is filterable and exportable. Nothing here can be edited after the fact.

Your data stays yours.

Customer-owned and exportable. We do not train on it. We do not sell it. We never mix it with another customer's. On your own infrastructure, it never leaves your perimeter.

  • No training on your data, ever.
  • Export everything on demand.
  • Delete everything, for real.

Compliance, built in. Not bolted on.

The controls are live in the product today. The formal certifications are admin in motion, and we'll tell you exactly where each one stands.

SOC 2 Type II
Controls in place, audit underway
Data residency
In-region deployment options
GDPR
Compliant
Encryption
At rest and in transit
Model access
Provisioned and governed by us
Your data
Customer-owned, exportable

We'd rather tell you exactly where we are than imply we're further along. Ask for the current report.

FAQ

The honest answers.

No dodging, no contact-sales-to-find-out.

Can this run inside our own environment?+
Yes, on the custom grade. On your infrastructure, fully inside your own cloud or data center, or as a dedicated isolated unit with in-region residency. On your infrastructure, your documents never leave your perimeter.
Whose models does it use?+
Model access is provisioned and governed as part of the deployment. We route to approved providers, in your region where required, and your data is never used to train models.
Is our data used to train models?+
No. Never. Not by us, and not by a model provider.
What happens if an AI employee gets something wrong?+
Its output is a draft until a named person approves it, so a wrong finding is caught at the approval step, not after the fact. Every action is logged, so review is always possible.
What do our auditors and regulators actually see?+
A complete trail: what was read, what was found, the reasoning, the evidence, the approver, and the timestamp. Filterable and exportable. Most manual processes produce far less.
Are you SOC 2 certified?+
The controls are live in the product today and the SOC 2 Type II audit is underway. We will show you exactly where it stands rather than imply we are further along.
What runs underneath?+
The runtime is Platos, which is open source, plus durable task infrastructure. Read it, audit it. We operate it in every deployment, including deployments on your infrastructure.

Bring your security team. We like the hard questions.

Ask for the deployment guide, the current compliance report, or a working session with your infosec review.

See it in action
Don't take our word for it

Work is better with Winsen.

Ask your favorite AI for a summary on Winsen. It opens with the question ready, so you get an honest read in one click.

Powered by winsen.ai/llms.txt