Every other tool searches everything, then filters the results. SCRS applies your permissions inside the search — material outside your remit is never retrieved, never ranked, never decrypted. That is the patent-pending part (UK Application 2602911.6). Personal data inside what you are cleared for is then tokenised before it reaches the model, and restored in the answer for you.
Point any MCP-capable assistant — including Microsoft Copilot — at your governed SCRS server.
Most “secure AI” tools search everything you own, then filter what comes back. By then the wrong record has already been read, ranked and scored. SCRS puts a gate inside the search, so the wrong record is never a candidate at all.
What we search and what we store are different places. The index holds only vectors and reference codes — no readable text. Your documents sit encrypted in a separate store. Reaching one gets you nothing without the other.
Your access scope is applied during the search, not after it. Anything outside your remit is never a candidate — never ranked, never scored, never returned. No scope means no results, not all results.
Only now is anything decrypted — and every reference is re-checked against your permissions first, independently of the search. Names, IDs and personal details are swapped for reversible tokens on the way out.
Claude, ChatGPT or a managed model reasons over tokens and answers. SCRS restores the real values for you afterwards — so you read a name, and the model only ever saw client_4821.
Connect the AI your team uses, and SCRS keeps a tamper-evident log of exactly what each model saw — and who asked.
| What the AI saw | Who asked | When |
|---|---|---|
| client_4821 · inv_7731 | A. Okafor | 10:24 |
| patient_2290 | R. Shah | 10:19 |
| client_3140 · ni_**** | A. Okafor | 09:52 |
Every question, retrieval and answer — hash-chained and exportable. Real names never appear in the model’s view.
SCRS publishes your governed AI as a secure MCP server. Point Claude, ChatGPT or your automation stack at it — answers are pseudonymised before they leave, and every request stays inside your governed SCRS plan.
Requires an SCRS workspace with the connector switched on — see the developer docs.
Not a policy PDF — controls enforced in the pipeline, on every request, for every user.
Originals live in a separate encrypted store; the AI’s search index holds only pseudonyms — never plaintext client data.
Every question, retrieval and answer is logged in a per-company, hash-chained trail you can export for review.
Revoke a person or a whole matter in one click — their access and the data they could reach are cut off instantly.
Delete a document and its keys are destroyed — the content is unrecoverable, and your storage is freed.
Scope who can retrieve what. Ethical walls keep one matter’s data out of another’s answers.
Bring your own model keys (OpenAI, Anthropic, Google, xAI) or use SCRS-managed keys — either way, data is redacted first.
SCRS gives you the paper trail: what the AI saw, who asked, and proof that the real client identifiers never reached the model. Subject-access and record-keeping obligations become a report, not a fire drill.
Priced per company, not per seat. Sign up and get started in minutes — add capacity as you grow.
Includes a monthly allowance of 7M tokens of governed AI — enough for everyday use across your team — plus 5 GB encrypted storage.
Other Me is our all-in-one workspace — AI assistants, CRM, email, documents, live chat, tickets and automation — SCRS-governed by default. The same firewall, wrapped around a full suite of business tools.
Including the ones that are easier to leave out.
No — and be wary of anyone who says otherwise. MCP, the open standard these connectors use, is a way for an assistant to call a tool. It is not a way to sit in front of one. The assistant reads your message first and decides for itself whether to call SCRS. Whatever you type goes to that assistant's provider exactly as it always did.
Your knowledge base. When the assistant asks SCRS a question, retrieval stays inside the permissions you configured, detected personal identifiers are replaced with placeholder tokens before anything leaves us, and the release is recorded in your hash-chained audit log. The assistant sees [PERSON_1], never your client's real name. That is a real and unusual guarantee — it is just a guarantee about your data, not about the assistant's whole conversation.
Use a surface we control. In the Other Me application, in SCRS Chat, and in your own product via the SCRS API or embeddable widget, the firewall runs on every request, fails closed if it cannot run, and has no user-facing off switch. If your obligations require that every interaction is governed, that is the deployment to choose — and it is usually a few lines of code.
Any that speaks MCP. Your SCRS workspace publishes one server URL secured with OAuth 2.1 — paste it into Claude, ChatGPT, Cursor, VS Code, Claude Code, or an automation platform like Zapier or n8n. There is no per-tool integration to build and no API key to hand around; each person signs in as themselves and sees only what they are allowed to see.
In a third-party assistant, largely yes — naming it (“ask SCRS what our payment terms are”) is the reliable way. Standing instructions help: a Claude Project, a ChatGPT custom instruction, or org-wide instructions on a Claude Team or Enterprise plan, which every member gets and nobody can edit. Those raise how often it is used; they do not make it certain. Our own surfaces need no such habit.
No, and we won't pretend it is. Pseudonymisation is a recognised safeguard under Article 4(5) of the UK/EU GDPR, and pseudonymised data remains personal data — the reversal key stays in your vault rather than travelling with the text. Detection is regex plus named-entity recognition: strong, and best-effort rather than a mathematical proof of completeness. Treat it as a control that reduces exposure, not as a licence to stop applying data-protection law.
Not yet. We hold no ISO 27001 or SOC 2 certificate and have not completed a third-party penetration test, and we will say so plainly rather than imply otherwise. What we can show you is the architecture, the audit trail, and the patent-pending scope-constrained retrieval that the rest of this page describes. If a certificate is a hard requirement for you today, we are not yet the right supplier.
Immediately, and centrally. Deactivating a member stops every governed call they could make — including through a connector they had already approved in their own Claude account — because access is resolved per person on every request, not baked into a token they keep. An admin can also revoke all assistant connections at once from the AI module.
See SCRS govern a real request against your own workflow. Real client identifiers never reach the model — that’s the whole point.