ACHI AI← All docs
Prepared for QEC · ConfidentialJuly 2026 · Version 1.0

Enterprise Security & Design Partner Evaluation Pack

ACHI Infrastructure & AI Governance Specifications — prepared specifically for Qulliq Energy Corporation covering Platform Security, Responsible AI Safeguards, Founding Design Partner Framework, and Enterprise Deployment Options.

Target Organisation

Qulliq Energy Corporation (QEC)

Attention

Tim, Head of Information Technology

Prepared by

Dormot Technologies (ACHI Platform Team)

Document 1 — Platform Security Architecture

Built on enterprise-grade infrastructure with strict data isolation.

ACHI is built around two fundamental security principles: absolute data ownership — QEC retains 100% ownership and control over all data, forms, submissions, and workflow logs — and deterministic governance, where AI capabilities operate strictly as advisory tools and never make autonomous decisions.

Cloud Architecture

AWS UK/EU

Hosted on AWS infrastructure in secure Europe (UK/EU) data centres. Containerised microservices with strict resource isolation, rapid security patching, and environment reproducibility.

Network Isolation

VPC Isolated

All internal service communications run within isolated Virtual Private Clouds (VPCs) with strict Security Group boundaries. External exposure restricted to authenticated HTTPS endpoints behind WAF.

Encryption in Transit

TLS 1.3

All data moving between browsers, internal APIs, and external integrations is encrypted using mandatory TLS 1.3 / TLS 1.2 with strong cipher suites. Unencrypted HTTP traffic is automatically rejected.

Encryption at Rest

AES-256

All application databases, file attachments, server logs, and persistent caches are encrypted at rest using AES-256 encryption.

Multi-Tenant Isolation

ACHI employs database-level Row-Level Security (RLS) using immutable tenant boundaries (org_id). Every database query, API call, and file access request programmatically validates the caller's organisation context.

Cross-tenant leakage structurally impossible

Access Control & Audit

  • System Roles: Owner, Administrator, Manager, Reviewer, Viewer
  • Business Roles: Route tasks to roles, never named individuals
  • Append-only immutable audit logs for all significant actions
  • Daily snapshot backups with PITR — RTO < 2h, RPO < 1h

AI Security & Safeguards

Deterministic AI Governance — AI proposes, humans decide.

ACHI enforces a strict Deterministic AI Governance Model to directly address enterprise security and operational risk. AI capabilities operate strictly as advisory tools — they never make autonomous decisions, modify execution state, or bypass business rules without human authorisation.

Governance Flow

User Input

Prompt / Form Submission

AI Layer

Generates proposals & drafts only

Human Gate

Authorised user accepts, modifies, or rejects

Engine

Executes state changes, approvals & audit trail

No Autonomous Decisions

AI never makes autonomous business decisions of any kind.

No Financial Execution

AI cannot approve purchases, contracts, or payments.

No Policy Overrides

AI cannot override corporate approval hierarchies or bypass assigned business roles.

Advisory Only

AI generates drafts and summaries — it never executes them directly.

Zero System Alteration

AI cannot publish or modify active workflows without explicit user authorisation.

Mandatory Human Approval

All AI-assisted actions operate in a proposal state — AI proposes, human decides.

Data Privacy & Infrastructure Roadmap

Zero model training. Full data ownership. Canadian residency available.

Data Usage Policy

Customer data, submissions, attachments, and prompt interactions are never used to train, fine-tune, or improve public or private AI models.

Zero Model Training

KMS & Encryption Roadmap

Current SaaS uses managed AWS KMS encryption. Enterprise roadmap includes support for Customer-Managed Keys (BYOK via AWS KMS).

BYOK Roadmap

Canadian Data Residency for QEC

While ACHI's public multi-tenant SaaS operates in AWS Europe, QEC can achieve immediate Canadian data residency (AWS ca-central-1 Montreal/Calgary) via the Customer Cloud / VPC Deployment Option (Option 3).

Document 2 — Responsible AI & Governance

AI supports decision-making. People remain accountable for decisions.

ACHI is designed around Deterministic Process Automation. We strictly decouple AI assistance from workflow execution. AI in ACHI functions as a high-intelligence assistant, while process logic, state execution, financial approvals, and governance remain 100% human-controlled and rule-bound.

Three-Tier Governance Architecture

Tier 1 · AI Layer

Generation & Structuring

User inputs a prompt. AI generates a structured JSON proposal containing form fields and stage definitions.

Unpublished Draft

Tier 2 · Engine Layer

Validation & Schema Check

ACHI's core engine validates the proposal against strict system Zod schemas, security rules, and data types.

Validated Draft

Tier 3 · Human Layer

Review & Execution

The System Administrator reviews the template, edits fields, and explicitly clicks Publish. Only upon human sign-off does the process become active.

Published / Active

AI Boundary Matrix

What AI can and cannot do in ACHI.

Functional DomainAI Can DoAI Cannot Do

Form Design

  • Generate form templates from natural language
  • Suggest field types, labels, and validation
  • Publish forms without admin sign-off
  • Modify active form schemas

Workflow Design

  • Draft multi-stage routing rules
  • Suggest relevant Business Roles as approvers
  • Publish workflows autonomously
  • Alter corporate approval hierarchies

Process Execution

  • Summarise submissions
  • Detect missing info and flag compliance anomalies
  • Surface risks and budget issues
  • Approve financial disbursements
  • Execute legal agreements
  • Override or bypass assigned business roles

Document 3 — Founding Design Partner Programme

An exclusive collaborative initiative to deploy ACHI in a real enterprise environment.

The ACHI Founding Design Partner Programme is designed to validate, refine, and deploy ACHI's AI Workflow Intelligence Platform within a real-world enterprise environment, automating a key business process while shaping ACHI's product roadmap.

Discovery & Workflow Mapping

Structured sessions with ACHI technical co-founders to map and optimise chosen operational workflows.

Implementation & Configuration

Setup of one (1) high-impact operational workflow, including form template design, business role mapping, and automated routing rules.

Tailored AI Automation

Customisation of AI copilot prompts, submission summarisations, and risk detection tailored to QEC terminology.

Training & Enablement

Comprehensive training sessions for System Administrators, Business Role Reviewers, and operational staff.

Priority Support & Founder Access

Direct Slack/Teams channel and weekly syncs with ACHI technical founders throughout the engagement.

6-Week Implementation Timeline

Week 1

Discovery & Mapping

Workflow analysis, Business Role definition, and success metric baselining.

Week 2

Build & Configure

Templates, role routing rules, AI prompt tuning, and administrator sign-off.

Wks 3–5

Operational Trial

Live execution, user feedback capture, and iterative optimisation.

Week 6

Final Review

Review against success criteria, executive demo, and Recommendation Report delivery.

Document 4 — Design Partner Trial Specification

Trial scope, benchmarks, and success metrics.

6 Weeks

Duration

1 Department

Department Scope

1 Workflow

Process Scope

Up to 25 Users

User Allocation

ObjectiveSuccess MetricTarget Benchmark

Reduced Manual Effort

Reduction in manual email follow-ups and administrative overhead

> 50% reduction in admin effort

Faster Approvals

Total cycle time from submission to final sign-off

> 40% faster approval time

Standardised Process

Percentage of submissions adhering to required fields and validations

100% compliance with schema

Process Visibility

Real-time tracking of active stages and bottlenecks

100% auditability across tasks

Document 5 — Enterprise Deployment Options

Four deployment models to meet QEC's regulatory and operational requirements.

1

ACHI SaaS Cloud

Multi-tenant SaaS managed by ACHI. Logical database isolation.

Infrastructure:AWS Europe (UK/EU)
Data Residency:AWS Europe
Key Management:ACHI Managed KMS
2

Dedicated Cloud

Single-tenant instance isolated at container and database level.

Infrastructure:Dedicated AWS Environment
Data Residency:Customer Choice (e.g. AWS Canada)
Key Management:Dedicated AWS KMS
3Recommended for QEC

Customer Cloud (VPC)

Deployed directly into customer's cloud via IaC templates. Recommended for QEC Canadian data residency.

Infrastructure:Customer AWS Account
Data Residency:Customer AWS (e.g. ca-central-1)
Key Management:Customer Managed KMS (BYOK)
4

On-Premise / Private

Enterprise deployment inside local private cloud or datacentre.

Infrastructure:Customer Private Kubernetes
Data Residency:Local Datacentre
Key Management:Hardware Security Module (HSM)