Security & Privacy

Trust Center

Last updated:

Your data deserves the same rigor as your client work.

InnovAItion Partners serves law firms, marketing agencies, and PR firms where confidentiality is non-negotiable. This Trust Center explains how we protect your data — and how our primary platform, Suits.ai, keeps it secure.

Start your security review

Security is embedded in how we work

InnovAItion Partners helps professional services firms — law firms, marketing communications agencies, and public relations firms — use AI to grow faster without compromising the confidentiality their clients expect. Most client data lives on the Suits.ai platform, which holds SOC 2 Type 2 and Google CASA Tier 2 certifications. We layer our services on top of that foundation using Anthropic Claude, Google Gemini, and Google Cloud Platform — all governed by Data Protection Agreements that prohibit model training on your data.

Absolutely not used for model training. We have signed Data Protection Agreements with OpenAI, Anthropic, and Gemini — made directly or via Suits.ai — that explicitly guarantee your information is never shared with other entities or used to train external models.

Certifications & standards

The Suits.ai platform — where most of our client data resides — maintains independent security certifications. InnovAItion Partners inherits these controls and adds contractual protections across all AI providers we use.

SOC 2 Type 2

The Suits.ai platform and its core infrastructure are independently audited and certified under SOC 2 Type 2.

Suits.ai Trust Center →
Google CASA Tier 2

Suits.ai holds Google CASA Tier 2 certification, verifying application security controls for AI platforms.

Suits.ai Trust Center →
GDPR Aligned

The Suits.ai offering complies with GDPR requirements. All data is currently stored in the United States.

TLS 1.2+ / AES-256

Data is encrypted in transit using TLS 1.2+ and at rest using AES-256 encryption on Google Cloud Platform.

The tools behind our services

InnovAItion Partners delivers AI-powered workflows using a carefully selected stack. Each component plays a defined role in how your data is stored, processed, and protected.

Primary platform
Suits.ai (opens in new tab)

Most client data is stored and processed on the Suits.ai platform — our core workflow and collaboration environment for professional services firms.

AI model provider
Anthropic Claude

Used for content generation and analysis under DPAs that prohibit model training on your data. Queries are processed in the moment with no persistent retention.

AI model provider
OpenAI

Used for select content and analysis workflows under DPAs that prohibit model training on your data. Queries are processed in the moment with no persistent retention.

AI model provider
Google Gemini

Used alongside Claude and OpenAI for select workflows. Covered by Data Protection Agreements ensuring client data is never used for model training.

Cloud infrastructure
Google Cloud Platform

All collected data is stored on GCP with enterprise-grade protection, continuous monitoring, and encryption at rest and in transit.

How we protect your data

These controls apply across the InnovAItion Partners services layer and the Suits.ai platform where your data is stored and processed.

No model training

DPAs with OpenAI, Anthropic, and Gemini explicitly guarantee your data is never used to train public AI models.

End-to-end encryption

TLS 1.2+ in transit and AES-256 at rest on Google Cloud Platform infrastructure.

Client data isolation

Fully isolated storage scoped by unique IDs — enforced at application, database, and vector store levels.

Role-based access

Granular RBAC via Clerk ensures AI results reflect only the data each user is authorized to access.

Secure integrations

OAuth via Paragon iPaaS with read-only, least-privilege connections. No raw credentials stored.

Data deletion on request

Full data deletion upon request, with AI provider DPAs committing to removal within 30 days of termination.

Integrations are optional. You are not required to connect internal data sources such as email or shared files. When you do, folder- and directory-level controls let you exclude sensitive repositories, and all connections use read-only, least-privilege OAuth via Paragon iPaaS.

Data privacy & confidentiality

InnovAItion Partners solutions for professional services firms are provided alongside industry AI leaders, including Anthropic, Google, OpenAI, and Suits.ai. The following FAQ addresses common questions and concerns raised by our professional services clients about our use of these tools in delivering our services.

1. Will our firm’s proprietary data be used to train public AI models?

Absolutely not. InnovAItion Partners ensures that your client data is never used for any purposes beyond your specific requests. We have signed Data Protection Agreements (DPAs) or equivalents with all major Large Language Model (LLM) providers, including OpenAI, Anthropic, and Gemini. These agreements, made directly or via Suits.ai, explicitly guarantee that “no data is used for model training,” ensuring your information is never shared with other entities or used to train external models.

2. Where is our data stored, and how is it secured against breaches?

All collected data is stored on the Google Cloud Platform (GCP), utilizing enterprise-grade protection and continuous monitoring. Data is encrypted end-to-end: in transit using TLS 1.2+ and at rest using AES-256 encryption. Furthermore, the Suits.ai platform and its core infrastructure components are SOC 2 Type 2 Certified. All data is currently stored in the United States.

3. How is our data protected from being commingled with other clients’ data?

Client data segmentation is a critical priority. All client data is stored in a fully isolated manner and scoped by unique IDs to ensure it cannot be mixed with other accounts. This strict data isolation is enforced at both the application and infrastructure levels, including our databases and vector stores. We also maintain complete separation between production and development environments.

4. How does the AI respect our internal security permissions and access hierarchies?

The Suits.ai platform uses granular, person-by-person access controls managed securely via Clerk. The platform completely respects your existing data access hierarchies and enforces Role-Based Access Control (RBAC) with least-privilege principles. Consequently, AI results are based solely on the data a specific user has access to, ensuring that junior staff cannot access partner-level confidential data through the AI.

5. Will Suits.ai store our system passwords or integration credentials?

No. All OAuth and credential handling is SOC 2 Type II compliant, meaning no raw data or credentials are ever stored in our backend. Integrations are handled via Paragon iPaaS using secure, read-only, least-privilege API connections. Paragon is the leading integration infrastructure platform for AI.

6. Do you require that we integrate our internal data (e.g., email, shared files, etc.) with the platform?

No, integration of additional internal sources is optional. While our AI workflows tend to perform better when provided with additional background and reference information, that improvement is generally marginal for our most commonly used workflows. A relatively small percentage of our professional services clients in regulated industries integrate with a private data source.

7. If we do decide to integrate, can we exclude highly sensitive folders or repositories from the platform?

Yes, you maintain full control over what data sources are integrated. We offer granular integration controls that enable folder- or directory-level imports when connecting to systems such as Google Drive or SharePoint. Because the platform uses read-only, least-privilege access, it will collect and use only the data repositories you explicitly authorize.

8. Does the platform support enterprise Single Sign-On (SSO) and Multi-Factor Authentication (MFA)?

Yes. For standard SSO sign-ins (such as via Google or Microsoft), the platform natively follows the MFA security settings set by your provider. If your firm requires integration with a one-off enterprise identity provider via SAML (e.g., an internal ADFS server), this is fully supported as an additional feature.

9. Is your platform GDPR compliant?

InnovAItion Partners generally does not act in either a Data Controller or a Data Processor capacity, but it does maintain privacy policies. The Suits.ai offering complies with GDPR regulations and requirements, which are largely a subset of the SOC 2 certification requirements. All data is stored in the United States.

10. How Suits.ai Connects to Your Systems

Suits connects to systems like HubSpot and Outlook through their official, standard integration points (OAuth-based APIs) — the same secure method used by any trusted business application.

  • Read-only by default — Suits only reads what it needs to do its job. It doesn’t write, modify, or delete anything in your systems unless you explicitly set it up to.
  • Targeted access only — Suits pulls the specific data relevant to your configured workflows, not a blanket sweep of everything.
  • No custom backdoors — everything runs through the standard, approved provider connection points (e.g., HubSpot and Microsoft).

11. What Happens to Your Data in the Suits.ai platform

This is the big one — and the answer is straightforward:

  • Minimal storage — Suits only retains what’s necessary to run your workflows and deliver outputs. It is not building a database of your client information.
  • Your data is never used to train AI models — We have signed Data Processing Agreements (DPAs) with both OpenAI and Anthropic that legally prohibit this. What goes in stays confidential.
  • AI providers don’t retain your data — When a query is processed, the AI handles it in the moment and moves on. There is no persistent storage of your data on OpenAI’s or Anthropic’s side beyond the immediate request.
  • Infrastructure — All data is stored on Google Cloud Platform (GCP), one of the most secure and compliant cloud environments in the world.

12. How Your Data Is Kept Separate from Other Customers in the Suits.ai platform

Think of it like a bank vault with individual safety deposit boxes:

  • At the corporate level — Each customer environment is logically isolated using unique identifiers. Your data never mingles with another firm’s data. This is enforced both at the Suits platform level and at the AI provider level (OpenAI and Anthropic both use logical data segregation as a core control).
  • At the individual level — Within your organization, access is governed by user-level permissions. Only the people you designate can see what they’re supposed to see.
  • Certified and audited — Suits is SOC 2 Type 2 and Google CASA Tier 2 certified — meaning independent auditors have verified that these controls actually work, not just that they exist on paper.

13. What Happens If You Turn It Off

  • Instant revocation — You can disconnect Suits from the integrated systems (e.g., HubSpot, Outlook) at any time, immediately, from within the platform. Access is cut off the moment you do.
  • Full data deletion on request — Per our agreements (and our DPAs with AI providers), all your data can be deleted upon request. Anthropic’s DPA, for example, commits to deletion within 30 days of termination.
  • Nothing lingers — Once disconnected and deletion is requested, there are no residual copies sitting in our systems or our AI partners’ systems.

Questions about security or privacy?

We welcome detailed security reviews from law firms, agencies, and PR firms evaluating our services. Email our security team and we will respond to every inquiry.