Security First
Both our Insights proprietary system and Open AI are built from the ground up for data security and are fully GDPR compliant.
Q: I understand you use Open AI. Will my data be used to train their AI models? What security considerations are there?
A: Absolutely not. Open AI's API is built from the ground up around security and does not use data presented to it to train their models. Data is used solely for the purpose of completing the tasks directly initiated by your engineers.
Any information sent to Open AI for suggesting fixes or summarising content is encrypted in transit with TLS 1.2 and at rest with AES-256.
Some data may be securely stored by Open AI for up to 30 days in order for them to check for abuse of their system. We have also applied for their zero-day retention policy.
You can access Open AI's trust section here for more information: https://trust.openai.com/
Q: How does the use of AI affect GDPR?
A: Open AI satisfies the requirements of the UK's GDPR and we're working with compliance specialists to provide certification to satisfy our clients who work within regulated industries such as healthcare or finance.
As Dark Laboratories will be processing data on your behalf, you will need up update your policies to reference Dark Laboratories Ltd.
Simply add "Dark Laboratories LTD" into your list of Third Party Processors.
Q: What about Insights' servers? What information do you store on your own Insights systems?
A: Our own system does not hold any of your ConnectWise ticket information aside from job notes optionally entered by your engineers in order to format them correctly, as well as usage statistics.
Our own servers are private, dedicated machines with strict access controls, rather than living "in the cloud" on someone else's shared computing.
We hold your ConnectWise API keys, stored encrypted on our private servers. All interaction with the ConnectWise API is conducted server-side so your API keys are never exposed client-side.
Q: I see you integrate with IT Glue, how does this affect security of our client's data?
A: Our IT Glue Integration currently provides quick-links directly to your customer data inside IT Glue. We do not store or process any information held in IT Glue, aside from pulling your list of customer names and internal IDs in order to build the links out to their data pages within IT Glue. These links open a new tab direct to your customer's data inside IT Glue, where normal IT Glue logons and access are still required.
If you choose to use our IT Glue integration, your IT Glue API keys will also be stored on our private servers, again encrypted and again only ever used server-side.
AI is an evolving field and we are committed to keeping on top of regulations as they change.