The Suits.ai platform and its core infrastructure are independently audited and certified under SOC 2 Type 2.
Suits.ai Trust Center →Security & Privacy
Trust Center
Last updated:
Your data deserves the same rigor as your client work.
InnovAItion Partners serves law firms, marketing agencies, and PR firms where confidentiality is non-negotiable. This Trust Center explains how we protect your data — and how our primary platform, Suits.ai, keeps it secure.
Get started
Start your security review
Review our security posture
Learn how InnovAItion Partners and Suits.ai protect client data for professional services firms.
View overview →Platform compliance documents
Access SOC 2 attestations and security documentation for the Suits.ai platform directly.
Open Suits Trust Center → (opens in new tab)Ask for information
Contact InnovAItion Partners at security@innovaitionpartners.com for detailed answers about data privacy, security, or compliance.
Email us →Overview
Security is embedded in how we work
InnovAItion Partners helps professional services firms — law firms, marketing communications agencies, and public relations firms — use AI to grow faster without compromising the confidentiality their clients expect. Most client data lives on the Suits.ai platform, which holds SOC 2 Type 2 and Google CASA Tier 2 certifications. We layer our services on top of that foundation using Anthropic Claude, Google Gemini, and Google Cloud Platform — all governed by Data Protection Agreements that prohibit model training on your data.
Compliance
Certifications & standards
The Suits.ai platform — where most of our client data resides — maintains independent security certifications. InnovAItion Partners inherits these controls and adds contractual protections across all AI providers we use.
Suits.ai holds Google CASA Tier 2 certification, verifying application security controls for AI platforms.
Suits.ai Trust Center →The Suits.ai offering complies with GDPR requirements. All data is currently stored in the United States.
Data is encrypted in transit using TLS 1.2+ and at rest using AES-256 encryption on Google Cloud Platform.
Technology stack
The tools behind our services
InnovAItion Partners delivers AI-powered workflows using a carefully selected stack. Each component plays a defined role in how your data is stored, processed, and protected.
Most client data is stored and processed on the Suits.ai platform — our core workflow and collaboration environment for professional services firms.
Used for content generation and analysis under DPAs that prohibit model training on your data. Queries are processed in the moment with no persistent retention.
Used for select content and analysis workflows under DPAs that prohibit model training on your data. Queries are processed in the moment with no persistent retention.
Used alongside Claude and OpenAI for select workflows. Covered by Data Protection Agreements ensuring client data is never used for model training.
All collected data is stored on GCP with enterprise-grade protection, continuous monitoring, and encryption at rest and in transit.
Security pillars
How we protect your data
These controls apply across the InnovAItion Partners services layer and the Suits.ai platform where your data is stored and processed.
No model training
DPAs with OpenAI, Anthropic, and Gemini explicitly guarantee your data is never used to train public AI models.
End-to-end encryption
TLS 1.2+ in transit and AES-256 at rest on Google Cloud Platform infrastructure.
Client data isolation
Fully isolated storage scoped by unique IDs — enforced at application, database, and vector store levels.
Role-based access
Granular RBAC via Clerk ensures AI results reflect only the data each user is authorized to access.
Secure integrations
OAuth via Paragon iPaaS with read-only, least-privilege connections. No raw credentials stored.
Data deletion on request
Full data deletion upon request, with AI provider DPAs committing to removal within 30 days of termination.
FAQ
Data privacy & confidentiality
InnovAItion Partners solutions for professional services firms are provided alongside industry AI leaders, including Anthropic, Google, OpenAI, and Suits.ai. The following FAQ addresses common questions and concerns raised by our professional services clients about our use of these tools in delivering our services.
1. Will our firm’s proprietary data be used to train public AI models?
Absolutely not. InnovAItion Partners ensures that your client data is never used for any purposes beyond your specific requests. We have signed Data Protection Agreements (DPAs) or equivalents with all major Large Language Model (LLM) providers, including OpenAI, Anthropic, and Gemini. These agreements, made directly or via Suits.ai, explicitly guarantee that “no data is used for model training,” ensuring your information is never shared with other entities or used to train external models.
2. Where is our data stored, and how is it secured against breaches?
All collected data is stored on the Google Cloud Platform (GCP), utilizing enterprise-grade protection and continuous monitoring. Data is encrypted end-to-end: in transit using TLS 1.2+ and at rest using AES-256 encryption. Furthermore, the Suits.ai platform and its core infrastructure components are SOC 2 Type 2 Certified. All data is currently stored in the United States.
3. How is our data protected from being commingled with other clients’ data?
Client data segmentation is a critical priority. All client data is stored in a fully isolated manner and scoped by unique IDs to ensure it cannot be mixed with other accounts. This strict data isolation is enforced at both the application and infrastructure levels, including our databases and vector stores. We also maintain complete separation between production and development environments.
4. How does the AI respect our internal security permissions and access hierarchies?
The Suits.ai platform uses granular, person-by-person access controls managed securely via Clerk. The platform completely respects your existing data access hierarchies and enforces Role-Based Access Control (RBAC) with least-privilege principles. Consequently, AI results are based solely on the data a specific user has access to, ensuring that junior staff cannot access partner-level confidential data through the AI.
5. Will Suits.ai store our system passwords or integration credentials?
No. All OAuth and credential handling is SOC 2 Type II compliant, meaning no raw data or credentials are ever stored in our backend. Integrations are handled via Paragon iPaaS using secure, read-only, least-privilege API connections. Paragon is the leading integration infrastructure platform for AI.
6. Do you require that we integrate our internal data (e.g., email, shared files, etc.) with the platform?
No, integration of additional internal sources is optional. While our AI workflows tend to perform better when provided with additional background and reference information, that improvement is generally marginal for our most commonly used workflows. A relatively small percentage of our professional services clients in regulated industries integrate with a private data source.
7. If we do decide to integrate, can we exclude highly sensitive folders or repositories from the platform?
Yes, you maintain full control over what data sources are integrated. We offer granular integration controls that enable folder- or directory-level imports when connecting to systems such as Google Drive or SharePoint. Because the platform uses read-only, least-privilege access, it will collect and use only the data repositories you explicitly authorize.
8. Does the platform support enterprise Single Sign-On (SSO) and Multi-Factor Authentication (MFA)?
Yes. For standard SSO sign-ins (such as via Google or Microsoft), the platform natively follows the MFA security settings set by your provider. If your firm requires integration with a one-off enterprise identity provider via SAML (e.g., an internal ADFS server), this is fully supported as an additional feature.
9. Is your platform GDPR compliant?
InnovAItion Partners generally does not act in either a Data Controller or a Data Processor capacity, but it does maintain privacy policies. The Suits.ai offering complies with GDPR regulations and requirements, which are largely a subset of the SOC 2 certification requirements. All data is stored in the United States.
10. How Suits.ai Connects to Your Systems
Suits connects to systems like HubSpot and Outlook through their official, standard integration points (OAuth-based APIs) — the same secure method used by any trusted business application.
- Read-only by default — Suits only reads what it needs to do its job. It doesn’t write, modify, or delete anything in your systems unless you explicitly set it up to.
- Targeted access only — Suits pulls the specific data relevant to your configured workflows, not a blanket sweep of everything.
- No custom backdoors — everything runs through the standard, approved provider connection points (e.g., HubSpot and Microsoft).
11. What Happens to Your Data in the Suits.ai platform
This is the big one — and the answer is straightforward:
- Minimal storage — Suits only retains what’s necessary to run your workflows and deliver outputs. It is not building a database of your client information.
- Your data is never used to train AI models — We have signed Data Processing Agreements (DPAs) with both OpenAI and Anthropic that legally prohibit this. What goes in stays confidential.
- AI providers don’t retain your data — When a query is processed, the AI handles it in the moment and moves on. There is no persistent storage of your data on OpenAI’s or Anthropic’s side beyond the immediate request.
- Infrastructure — All data is stored on Google Cloud Platform (GCP), one of the most secure and compliant cloud environments in the world.
12. How Your Data Is Kept Separate from Other Customers in the Suits.ai platform
Think of it like a bank vault with individual safety deposit boxes:
- At the corporate level — Each customer environment is logically isolated using unique identifiers. Your data never mingles with another firm’s data. This is enforced both at the Suits platform level and at the AI provider level (OpenAI and Anthropic both use logical data segregation as a core control).
- At the individual level — Within your organization, access is governed by user-level permissions. Only the people you designate can see what they’re supposed to see.
- Certified and audited — Suits is SOC 2 Type 2 and Google CASA Tier 2 certified — meaning independent auditors have verified that these controls actually work, not just that they exist on paper.
13. What Happens If You Turn It Off
- Instant revocation — You can disconnect Suits from the integrated systems (e.g., HubSpot, Outlook) at any time, immediately, from within the platform. Access is cut off the moment you do.
- Full data deletion on request — Per our agreements (and our DPAs with AI providers), all your data can be deleted upon request. Anthropic’s DPA, for example, commits to deletion within 30 days of termination.
- Nothing lingers — Once disconnected and deletion is requested, there are no residual copies sitting in our systems or our AI partners’ systems.
Questions about security or privacy?
We welcome detailed security reviews from law firms, agencies, and PR firms evaluating our services. Email our security team and we will respond to every inquiry.