The agent answers only from documents a client supplies, every answer is traceable to the page it came from, the client keeps ownership of their documents and question log, and nothing in either is used to train a general model.
This page is written as documentation rather than marketing. It describes how the system is built, where the boundaries sit, and what is not in place yet.
An answer can only be produced from the documents a client has supplied and approved for use. The agent has no access to the public internet at answer time, no access to another client's corpus, and no general knowledge it is permitted to fall back on.
Every answer carries the document and the page it came from, so any answer can be checked against the source rather than taken on trust. Citations are verified on a sample at ingestion before a corpus proceeds, because a citation that opens at the wrong page is worse than no citation.
Superseded documents still in circulation are found and excluded by hand when the corpus is prepared. Stale literature is the main cause of wrong answers, and it is a documentation problem rather than a model problem.
The corpus is only ever documents you have already published. Data sheets, bulletins, installation guides, evaluation reports, the material already on your website and in your literature. We do not ingest internal documents, unreleased material, pricing files, correspondence or anything else you have not made public. That is a product boundary, not a policy we could quietly relax: an agent built on published literature cannot leak what it was never given.
Your own reps and technical staff can be given an internal channel onto that same public corpus, with their usage logged separately. Internal access, never internal documents.
These are not settings. They are the reason a technical department can put its name on the system.
When the answer is not in the corpus it says so, captures the contact and routes the question. It does not infer, and it does not hedge into language that reads like an answer.
Code interpretation is an engineering judgement with a consequence attached. The agent refuses and routes the question to a person.
Approving a build-up is a design authority decision. A vendor system has no standing to make it.
It answers about the client's products from the client's documents. It has no basis for a claim about anyone else's.
A separate quality process reviews conversations against the source documents: whether each claim is grounded in the cited passage, whether a refusal was correct in both directions, and whether anything safety-critical was answered with unwarranted confidence. It runs independently of the answering agent, and its output is an append-only log plus a weekly summary.
A refused question is not a dead end. The contact is captured, the question and the full conversation are routed to a named person on the client's side, and the escalation path is tested end to end before go-live. A refusal with nowhere to go is not a refusal, it is a lost enquiry.
Your documents, your corpus and your question log remain yours, and the agreement says so. If we part ways you leave with all of it, including every question anyone has asked.
Your documents and your question log are used to answer your questions and to produce your reports. They are not used to train a general model, and they are never used to answer another client's question.
Conversation data and captured contacts are passed to the CRM your team already works in, so a rep opens an enquiry knowing what was asked and what was answered.
The named parties are these. Your documents are processed by OpenAI to produce answers and embeddings. They are stored as vectors in Qdrant. The service runs on Render. Conversations reaching the website chat and the technical line pass through GoHighLevel, and escalation notices go out through an email provider. Hosting regions, the current sub-processor list and retention periods are set out in the agreement and stated in writing before you sign.
A technical line that answers calls, a quality process that reviews them, and an email or SMS follow-up carrying the sources cited all sit inside Canadian privacy and anti-spam law. Our position is that consent is designed into the flow at deployment rather than added afterwards, and that the wording is agreed with the client rather than assumed on their behalf.
This section states our position on consent. It is under review by counsel against PIPEDA, provincial privacy legislation and CASL, and will be updated if that review changes anything material.
Noremac AI is an early-stage company. It holds no SOC 2 report, no ISO certification and no third-party security audit. Nothing on this page has been externally verified. The controls described above are real and the certifications are not, and we would rather write that down than display a logo that implies otherwise.
There is also no named public reference and no signed customer yet. What exists is a product that has been built, evaluated against a manufacturer's documents, and put in a manufacturer's hands.
No. The corpus is only ever documents you have already published. We do not take internal documents, unreleased material, pricing files or correspondence, so there is nothing confidential of yours in the system to protect in the first place.
No. A client's documents and question log are used to answer that client's questions and to produce that client's reports. They are not used to train a general model.
The client and Noremac. The question log belongs to the client, and the agreement says so, including the right to leave with all of it.
Two things. It can only draw on the documents supplied, and it refuses rather than guessing when the answer is not there. Every conversation is then reviewed against the source documents by a separate quality check.
No. Noremac AI is an early-stage company and holds no third-party security certification. The controls described on this page are real and the certification is not, and we would rather say so than display a badge with nothing behind it.