Skip to content

Enterprise Readiness

Evaluating TACT for your organization

Written for HR, L&D, IT, security and procurement reviewers. Every capability below describes how TACT behaves today. Where something is not built, it says so plainly rather than implying a roadmap item is a feature.

Stated plainly: TACT holds no security certification (no SOC 2, no ISO 27001), publishes no compliance attestation, and has no SSO/SAML, SCIM, HRIS, LMS, Teams or Slack integration today. If your review requires any of those, tell us before you invest time — we would rather say so now.

Privacy

TACT is built for conversations people would not put in a shared document. Preparation content stays with the individual.

  • Before any text is sent to a model provider, TACT automatically removes names, companies, email addresses, phone numbers, links and similar identifiers, and stores only that scrubbed version.
  • Removal is pattern-based, not perfect. TACT tells users this in-product and asks them to describe roles and behaviour rather than real names.
  • Users are encouraged to describe a counterpart by role ("my direct report", "my skip-level") — preparation quality does not depend on real identities.

Not available today

  • TACT is not certified against a privacy framework and does not publish a privacy attestation.

Data handling

What TACT stores, where it lives, and who can read it.

  • Stored per user: account record, the conversations they prepare, practice transcripts, readiness scores, saved Playbook items and product usage events.
  • Data is held in a managed Postgres database with row-level security. Every row is scoped to the owning account; colleagues in the same organization cannot read another user's rows.
  • Product analytics events record the action and its context only — never conversation text.
  • All traffic runs over TLS. Application secrets are held in the server environment and are never exposed to the browser.

Not available today

  • Data residency cannot be selected by region today.
  • Customer-managed encryption keys are not offered.

AI usage

Which models are used, for what, and where the limits are.

  • TACT uses large language models to draft language, simulate a counterpart in practice, and score readiness across Tone, Aim, Clarity and Timing.
  • Requests are routed through a managed AI gateway to Google Gemini and OpenAI models. A user can choose which provider handles their requests in Settings.
  • Only the scrubbed version of the user's text is sent to the provider, together with TACT's own instructions.
  • AI can be confidently wrong. Every AI surface in the product carries that warning, and TACT is positioned as preparation — not legal advice, medical or mental-health advice, or HR investigation guidance.

Not available today

  • TACT does not offer a customer-selectable model list beyond the two providers above, and cannot run in a customer's own model tenancy.

Account security

How people get into a TACT account.

  • Email and password sign-in, with email confirmation and self-serve password reset.
  • Google sign-in for organizations that prefer not to manage another password.
  • Sessions are managed by the authentication service with rotating refresh tokens; sign-out revokes the session.
  • Server-side authorization on every privileged action — the client cannot grant itself access by editing a request.

Not available today

  • SSO/SAML and SCIM provisioning are not available today.
  • Enforced MFA and organization-level password policy are not available today.

Access controls

Roles inside an organization account.

  • Organization roles: owner, admin and member. Only owners and admins can invite people or change a member's role.
  • Invitations are email-scoped and expire; a member joins only by accepting an invitation sent to their address.
  • Platform administrator rights are held in a separate roles table, checked server-side — never inferred from a profile field or browser storage.
  • Every privileged action (invites, role changes, membership changes, comped access) writes an append-only internal audit record.

Not available today

  • Custom or granular role definitions beyond owner/admin/member are not configurable.
  • The audit record is internal — it is not exposed to customer administrators or exportable today.

Organizational reporting

What an HR, L&D or People Ops sponsor actually receives.

  • Participation and practice activity across the cohort.
  • Aggregate readiness across Tone, Aim, Clarity and Timing, and how those move between the start and end of a pilot.
  • Aggregate survey results from baseline and exit surveys.
  • Small-sample suppression: aggregate reporting is withheld entirely until a cohort has at least five responses, so a result cannot be traced to one person.

Not available today

  • Scheduled report delivery, custom dashboards and raw data export for BI tools are not available today.

Data retention

How long content is kept.

  • Content is retained for as long as the account exists, so that users can see their readiness trend over time.
  • Users can delete individual conversations and saved Playbook items at any time, and those rows are removed.
  • Backups of the managed database are retained by the hosting platform for operational recovery.

Not available today

  • Configurable retention windows (for example, auto-delete conversations after 30/90/365 days) are not available today. Retention is currently "until deleted".

Data deletion

Getting data out, and getting it removed.

  • Self-serve export: a user can download a machine-readable copy of their own data from Settings.
  • Self-serve deletion: a user can permanently delete their account from Settings. This removes their conversations, practice transcripts, readiness scores, Playbook items and profile, and deletes the authentication record.
  • Deletion on request for an organization sponsor: write to info@st4yreadyconsulting.com and we will action it.

Not available today

  • Bulk deletion by an organization administrator from the interface is not available today; it is handled as a support request.

Administrator visibility

The boundary that makes people willing to be honest in TACT.

  • Organization administrators see: who is participating, how often they practise, and aggregate readiness.
  • Organization administrators do not see: what conversation someone prepared, the text they wrote, their scripts, their practice transcripts, their reflections, or their individual survey comments.
  • Individual survey comments are never attributed back to a person in reporting.
  • TACT staff do not browse customer conversations as part of normal operation; access to production data is limited to the operator of the platform for support and incident response.

Not available today

  • There is no customer-facing log of staff access to production data.

AI training policy

What happens to content after it is used to produce a response.

  • TACT does not train, fine-tune or evaluate models on customer content.
  • TACT does not sell customer data, and does not share it with advertisers or data brokers.
  • Scrubbed text is sent to the model provider for the sole purpose of producing the response the user asked for, and is processed under that provider's API terms.

Not available today

  • TACT cannot yet hand you a signed, TACT-specific zero-retention or no-training addendum from the model providers. Requests are covered by the providers' standard API terms only.

High-risk conversation guardrails

Where TACT deliberately stops generating and points to a human.

  • Incoming situations are screened for high-risk signals: harassment, discrimination, retaliation, threats or violence, safety, legal exposure, medical and mental-health matters, and self-harm.
  • When a high-risk signal is detected, TACT surfaces a guardrail before generating: it names the risk, and directs the user to qualified support — HR or people team, employee assistance, occupational health, an employee representative, a qualified adviser, or crisis resources.
  • Public Script Library scenarios with high-risk exposure (layoff, performance improvement plan, reporting a colleague, reorganization, burnout) carry the same guidance, and it is shown even when the full script is gated.
  • TACT does not give legal or HR-compliance advice, and says so in-product.

Not available today

  • Guardrails are pattern-based screening plus model instruction, not a certified safety classifier, and can miss cases.

Security questionnaire process

How to run TACT through your review.

  • Send your questionnaire — your own template, a VSAQ/CAIQ-style workbook, or a short list of questions — to info@st4yreadyconsulting.com.
  • You will get written answers directly from the team that builds the product, with an explicit "not available today" wherever that is the honest answer.
  • This page is the standing reference: what is true today sits above, and anything you need that is missing can be raised in the same thread.

Not available today

  • TACT does not hold SOC 2, ISO 27001 or any other security certification, and does not have a completed standard questionnaire package or trust-portal listing.
  • A signed data processing agreement and a published subprocessor list are not available today.

Support and contact

Who to reach, and for what.

  • Security, privacy, procurement and data requests: info@st4yreadyconsulting.com.
  • Pilot scoping, organizational rollout and evaluation questions: schedule a discovery call and we will scope it live.
  • Product issues from named organizational sponsors are handled directly by the team that builds TACT.

Not available today

  • There is no 24/7 support desk, contractual SLA or dedicated technical account manager today.

Start a review

Send your questionnaire or your list of questions to info@st4yreadyconsulting.com. See also the Trust Center, privacy policy, terms, and AI disclaimer.

TACT uses AI to help prepare and practise conversations. AI can make mistakes and can be confidently wrong. TACT is not legal, HR-compliance, medical or mental-health advice.

TACT
TACT uses AI. AI can make mistakes — review every script before you use it, and confirm anything with legal, HR, or medical stakes with a qualified professional.