Skip to content

The system's limits, and who owns your data.

The autonomy level, the human approval, the data handover and what happens when something goes wrong are visible before any contract. We build trust with control points, not with promises.

SEE THE CONTROLS ↓
Autonomy
LEVEL 1–3
Critical action
HUMAN APPROVAL
Data space
PER CLIENT
Activity log
TRACEABLE
Handover
IN WRITING

THE LIMITS ARE WRITTEN IN THE CONTRACT

A critical decision does not get lost in the system.

Not every build has the same authority. Which step is automatic, which is recorded and which waits for human approval is written down process by process.

  1. 01CRITICAL DECISION

    Human approval

    Price, contract or quote sending, payment, first contact and data deletion wait for human approval.

  2. 02RECORDED

    Traceable action

    A record is kept of who did what and when; on low-risk, reversible steps the previous state is preserved.

  3. 03ISOLATED

    Separate working space

    A separate environment is set up for each client; no shared client data pool is used.

  4. 04PORTABLE

    Written handover

    The scope of the code, data and documentation handover is set out in the contract.

The system knows where to stop.

VUNTUS OPERATING RANGE / 01–03

The systems we build run in the 1–3 range. The exact level is written in the contract, process by process.

  1. 00READS

    Observation

    Reads the data, makes the state visible and reports. Takes no action.

  2. 01PREPARES

    Draft

    Prepares the reply or the output; a person checks it and sends it.

  3. 02CARRIES OUT

    Record

    Carries out low-risk, recorded and reversible actions.

  4. 03WITHIN THE RULES

    Limited action

    Moves within written rules; stops at price, money and contract.

  5. 04OUT OF SCOPE

    Full autonomy

    Decides without human control. We do not sell this level.

Your data is not held hostage; the system can be audited.

Ownership, access and activity history are controlled separately. That way trust rests on visible measures, not on a single claim of being “secure”.

OWNERSHIPWITH THE CLIENT
“Your data is not held hostage.”

If you leave, the scope of the code, data and documentation handover is written in the contract.

  • A separate working environment for each client
  • No shared client data pool
  • No model training on client data
01RBAC

Access roles

Each user reaches only the area their role requires.

02VAULT

Secret key management

Service keys are kept apart from the application code.

03AUDIT LOG

Records and logging

Critical actions leave a trail that can be examined later.

04SEPARATE SPACE

Isolated environment

Client work is not merged into a shared data pool.

If something goes wrong, the next step is already set.

We do not commit that no system ever makes a mistake. This is our commitment: what happens in case of an error, and who steps in, is written down in advance.

  1. 01

    Notice

    An unexpected result is seen from the activity log, not guessed at.

  2. 02

    Stop

    A suspect flow moves into a human queue instead of carrying on by itself.

  3. 03

    Roll back

    On actions the scope calls reversible, the previous state is preserved.

  4. 04

    Escalate

    A situation that cannot be resolved goes to a predefined role, not to one person.

Short answers to the hard questions.

Model dependency, the KVKK approach, the frameworks we use and the security reporting channel; written out plainly, without raising the level of the claim.

01Model and provider dependency

The system is not tied to a single provider. The model call sits in a layer of its own, apart from the business logic. Changing provider is maintenance work carried out in that layer, rather than building the whole system again.

  • The provider and the step in use are stated in the written scope.
  • Whether the model shows its source, avoids guessing, or hands over to a person is decided during the build.
02KVKK and the retention approach
  • There are separate privacy notices for the score and for the booking.
  • Explicit consent for the email series is asked for separately; the box does not arrive pre-ticked.
  • Score data is kept for 24 months. A request to delete it earlier can be sent through info@vuntus.com.
  • Cookieless analytics is the default; Google Analytics runs only with explicit consent.
03The frameworks we refer to

We refer to the NIST AI Risk Management Framework, the OWASP LLM Top 10 and the guidance of the Turkish Data Protection Authority in our design checklist. This is not a claim of certification.

04Security reporting channel

If you notice a security vulnerability, we ask you to tell us before making it public. We look into the report and share the outcome; we do not run a bounty programme.

Reporting address: info@vuntus.com

What we do not sell is as clear as what we do.

  • 01We do not sell level 4 autonomy
  • 02We do not guarantee outcomes
  • 03We do not enter every sector
  • 04We do not promise what we cannot measure

Trust questions do not wait until after discovery.

We settle the technical limits, the steps that need human approval and the data handover together, while the scope is still taking shape.

Request a Discovery Call