Built for buildings with a compliance floor.
A chatbot that says something wrong is awkward. An AI employee that does something wrong is a finding. So the wrong thing is hard to do, easy to catch, and always attributable to a named approver.
Permission. Approval. Audit.
The three questions every security team asks, answered by design.
Can it even see that?
An AI employee holds exactly the access you grant it. Nothing more. If your reviewer cannot open a file, neither can the employee working that queue. No new access surface. No data crossing team lines.
- →Access scoped per role, granted by you
- →Source-system permissions always respected
- →No "AI admin" backdoor to your data
Should it really do that?
Nothing an AI employee produces counts until a named person approves it. Findings, closures, dispositions: all drafts until sign-off. This is not a setting we added. It is the contract the product is built on.
- →Every output waits for a named approver
- →Every approval logged with its evidence
- →You grant autonomy per action type, and can revoke it
What exactly did it do?
Every read, every check, every draft, every approval is logged with its reasoning, the data it touched, and the outcome. Built to face internal audit, statutory auditors, and regulators. Not a black box. A glass one.
- →Every action carries its reasoning and evidence
- →Filter by employee, action, or outcome
- →Export on demand for compliance and audit
Deployed where your regulator is comfortable.
Three arrangements, two grades, one product. Managed SaaS for small teams. On your infrastructure and a dedicated isolated unit for enterprises: that is where single-tenant isolation lives. Same employees, same approvals, same audit trail, wherever it runs.
Managed SaaS
One shared multi-tenant deployment, run by us end to end. Encrypted, audited, exportable, and your data is never mixed with another customer's. Sign up and go.
On your infrastructure
Single-tenant, deployed in your own cloud or data center: your database, your storage, your domain. Documents never leave your perimeter. Winsen operates the runtime. Priced in the contract.
Dedicated isolated unit
A single-tenant deployment we host exclusively for you, in your region, on your custom domain. We operate it. Your security team inspects it. Most "it must be in-house" mandates actually need exactly this.
What the audit trail looks like.
One morning of one AI employee's work on one loan file. Every action, its evidence, and the person who signed off. This is what your auditor scrolls through.
Opened loan file HL-2847. 34 documents, scope: credit review.
Verified stated income against 12 months of bank statements. 2 discrepancies flagged.
Exception report drafted with both discrepancies and source pages attached. Waiting for approval.
Signed off by R. Mehta, Senior Credit Officer. Report released to the file.
Your data stays yours.
Customer-owned and exportable. We do not train on it. We do not sell it. We never mix it with another customer's. On your own infrastructure, it never leaves your perimeter.
- No training on your data, ever.
- Export everything on demand.
- Delete everything, for real.
Compliance, built in. Not bolted on.
The controls are live in the product today. The formal certifications are admin in motion, and we'll tell you exactly where each one stands.
We'd rather tell you exactly where we are than imply we're further along. Ask for the current report.
No black-box runtime. We show our work.
The engine under your AI employees is open and inspectable, not a proprietary mystery you have to trust.
Platos
The runtime your AI employees think on is open source. Not a proprietary black box you take on faith. Read it, audit it. We operate it in every deployment.
platos.dev →Trigger.dev
Every task and workflow runs on durable infrastructure: observable, retryable, inspectable. Long jobs survive restarts, and every run leaves a trace.
trigger.dev →The honest answers.
No dodging, no contact-sales-to-find-out.
Can this run inside our own environment?+
Whose models does it use?+
Is our data used to train models?+
What happens if an AI employee gets something wrong?+
What do our auditors and regulators actually see?+
Are you SOC 2 certified?+
What runs underneath?+
Bring your security team. We like the hard questions.
Ask for the deployment guide, the current compliance report, or a working session with your infosec review.


