Self-service export & deletion across all tenant data.
Per-tenant isolation, deny-by-default access, audit.
Human gate, cost & prompt governance on the Ai.
Data in eu-west-2, encrypted, audit-logged.
Architecture designed to these standards and shared with the wider estate. Certification in progress; documentation available under NDA.
No review or photo is reused without clearing the gate.
Google reviews are stripped of names, personal details and sensitive information before a single line is reused. Photo and asset uploads carry a consent step covering people, clients, vulnerable people, children, private homes and confidential information. Neither flow ships without its consent and stripping steps.
Shared login, separated data
TomSocial uses the same secure sign-in as TomPilot, so one account works across the estate. But its data lives in its own tables with deny-by-default access, and reads across modules go through read-only helpers. The strategy toggle pulls from TomPilot read-only; it can never write back.
deny-by-default RLS
read-only helper
Doing a due-diligence review?
We'll send the security pack, the consent and data-protection notes and a DPA. Straight answers from the people who built it.