Skip to content

Private AI that runs on your own premisesYour knowledge. Your control.

Seesa's models, company memory and agent execution run on your premises. Access to information and permission to take action are configured for your team and its connected systems.

Seesa

On your premises

Company memoryStored on your installation
Individual accessInformation appropriate to each person
Agreed actionsPermissions and approval points

What runs on your installation

The AI models, your company memory and the agent work run on the machine in your building. The models are from the Qwen family of open-weight models. Your company data is never used to train or fine-tune them.

What connects outside it

An on-premise installation is not disconnected, and we would rather list its connections than pretend there are none. This is what leaves the machine. The same list is written into the data processing agreement each customer signs, and we check it by packet capture before go-live.

Some components we ship have usage reporting built in by their makers. We are switching it off in the shipped configuration and re-running the packet capture before the next go-live; this page will be updated when that is done.

Your team's connection to Seesa

People open Seesa in a browser at a company address on seesa.ai. That connection travels through Cloudflare's network, which checks each sign-in and carries the traffic to the installation through an outbound tunnel. The encryption from the browser ends at Cloudflare's edge, so Cloudflare can see that traffic in transit. The models, company memory and files stay on the machine. If your security policy does not allow a third party in that path, tell us before go-live.

Connected systems

Connections to the systems you authorise, such as Microsoft 365, Google Workspace or Slack, go to those providers under your own authorisations, as they would for any software that reads them.

Web search and browsing

When a person or a routine asks Seesa to look something up, its agents search and read the public web from your internet connection. This can be switched off for your installation.

Health heartbeat

Every five minutes the installation tells Pentatonic its uptime, load, memory, disk, GPU and software versions, so we see faults early. It carries no company data. We can turn it off on request, at the cost of slower fault detection.

Software updates

The installation checks Pentatonic's software registry for new releases, pinned by content hash, and downloads them. It uploads nothing. You can ask for updates to be applied only on your approval.

Remote support

Named Pentatonic engineers support the installation over a remote connection. Console sessions are recorded, including what the engineer types, and the recordings are stored with Cloudflare for the period set in your data processing agreement. A standing administrative path also exists so we can recover a machine that cannot be reached any other way. It can be turned off for your installation, and it turns itself back on only if the machine restarts locked and unreachable.

Encrypted, with keys held on both sides

The machine is encrypted, and your company data sits on its own separate encrypted volume. The keys to that volume are held by two people: one named person at Pentatonic and one at your company.

Access follows the person

Each person's access governs what their Seesa can use. Sharing an answer does not have to mean sharing the records behind it.

Actions follow your rules

Set the permitted actions and approval rules for connected tools. Your team decides where Seesa can prepare work and where it can carry out agreed actions.

Learning means routines, not training

When we say Seesa learns from the work you do, we mean its agents notice processes your team repeats in the connected systems, such as sending the same email each week, filing or tagging emails, or updating a CRM, and suggest routines to automate them. Seesa has 140 ready-made routines, and your team can write its own. None of this trains or fine-tunes the AI models.

SOC 2 Type II

Pentatonic has a SOC 2 Type II report covering Pentatonic as a company. To request a copy, contact us.

Reporting a security issue

If you think you have found a security issue in Seesa or this website, email hello@seesa.ai with the details. Our security.txt file is at seesa.ai/.well-known/security.txt.

Security questions for your deployment

We review remote access, updates, retention and recovery against the proposed installation, and set them out for you before it goes live.

Questions, answered.

Does our company data leave our building?

Seesa's models, company memory and agent work run on the installation on your premises. On-prem doesn't mean disconnected. Your team reaches Seesa through Cloudflare, which checks sign-in and carries that traffic; connected systems are reached at their providers; agents search the web when asked; a health heartbeat and software updates talk to Pentatonic; and support uses a documented remote connection. The full list is in the section above and in your data processing agreement.

Is our data used to train the AI?

No. Your company data is never used to train or fine-tune the AI models, which are from the Qwen family and run on your installation.

Do you have SOC 2?

Pentatonic has a SOC 2 Type II report covering Pentatonic as a company. Contact us to request a copy.

Who holds the encryption keys?

Company data is on a separate encrypted volume. Its keys are held by one named person at Pentatonic and one at your company.

Who can see what in Seesa?

Each person's access governs what their Seesa can use. Sharing an answer does not have to mean sharing the records behind it.

Can Seesa act without approval?

Only where you allow it. For each connected tool you choose whether Seesa can read, prepare a draft or carry out an agreed action, and your approval rules decide when it stops for a person.

Who maintains the system?

Pentatonic maintains the software and configuration of the systems it supplies. The support connection, permissions and data-access arrangements are documented before go-live.

Discuss your requirements.

Bring your security questions to the deployment conversation.

Talk to us about security