Skip to content
Systems AI

You see every step, every source and every decision

This page lists the controls that exist, the records the system keeps, and the certifications we do not hold. Nothing here is aspirational.

Editorial review is a step, not a policy

Approval gates, manual field edits and input stops are steps inside the route.

Production does not continue past a gate until a person moves it.

The automation level is set per route by the customer, not by us.

A policy that says "a human reviews everything" is a statement. A route that cannot continue without a confirmation is a mechanism. Procurement can inspect the second one.

Every piece carries its own record

Which source the item came from.

Which steps ran, in what order, with which prompts.

Which artefacts each step produced, including intermediate versions.

Retry history and final state.

That an editor confirmed before publication.

Until a per-step record of exactly which user approved which gate and when is confirmed, this page describes what the system records — and does not present it as a compliance artefact.

Where regulation meets the architecture

Who can reach what

  • Provider keys are encrypted (AES-256-GCM),and access to a specific key can be restricted to specific media units.
  • Roles are scoped per media unit.Permitted routes, AI profiles and prompts are configured per unit.
  • Platform administrators on the vendor sidehold technical access to every contour of a deployment. The scope and handling of that access is set in the contract — we state it first because it is the first question on any security questionnaire.
  • Sign-in is through SSO (Keycloak),with no separate passwords inside Genix. Connecting your own identity provider is discussed during rollout.
  • Artefacts are stored in S3-compatible storage.

Spend is metered and capped where it matters most

Every paid AI call is metered: tokens, speech characters, images, video minutes, call count.

Limits on those counters are enforced by the system, globally and per media unit.

Speech recognition, web search and page retrieval are metered but governed by the contract rather than a hard cap — we say which is which rather than implying everything is capped.

Spend is visible per brand, so a single scenario does not quietly absorb a group budget.

No certifications, stated plainly

We do not hold SOC 2, ISO 27001 or a published penetration test report. We do not claim "enterprise-grade security", because that phrase means nothing without an audit behind it. If a certification is a precondition for you, we are not a fit today, and we will say so on the first call rather than in month three of procurement.

Who you would be contracting with

The contracting entity behind Genix is SYSTEMS AI LLC (ТОВ «СИСТЕМС АІ»), a limited liability company incorporated under the laws of Ukraine. Company ID (EDRPOU) 46332353. Registered in Kyiv, Ukraine.

Genix is the product name. There is no company called Genix.

The platform was built inside a Ukrainian media group that publishes at high volume under conditions that leave no room for a process that only works on good days. That is where the product's bias towards visibility, retries and explicit human checkpoints comes from.

Bring your security questionnaire

We would rather answer it before the pilot than during it. Book a call and send the questionnaire in advance.

Book a call
See how we work
What we can prove, and what we cannot