Security and Data Handling
Running a vendor security review? This page answers the questions your team usually asks. For formal documentation, including NDA, DPA, and AI usage statement, email hello@grovedeck.com directly. A Certified Cornerstone Expert responds, not a form.
How access works
You provision our access. You define the scope. You revoke it in a click.
- Least-privilege access only, scoped to what the work requires.
- No standing admin access beyond active engagement scope, and no production credentials kept between engagements.
- Access is provisioned and deprovisioned through your own Cornerstone system controls.
- We work within whatever access review cadence your security team runs.
- Nothing requires us to bypass Cornerstone’s own access controls. We operate inside them.
Data handling
Your training records, configurations, and reports stay in your Cornerstone system. The tooling we built and maintain in house reads what it needs in the moment. It doesn’t replicate your data to external storage or export records outside your environment.
We use AI inside that tooling, and it does not train external models on your data. Nothing it reads becomes training input for any external model: not training records, not completion histories, not org structures, not permissions, not learning assignments, not anything else our tooling or the AI inside it touches in your system.
Compliance posture
- NDA and Data Processing Agreement signed before access is provisioned.
- GDPR-aligned handling for UK and EU clients, including data residency.
- CCPA and state privacy law-aware for US clients.
- Cornerstone’s own data controls remain authoritative. We don’t override system-level privacy settings.
- Subprocessor list available on request.
AI governance
We use AI in our own tooling to read your system, watch for drift, and work out what is worth changing. It operates inside the guardrails your security and HR teams have already set, and nothing reaches your live platform without a person approving that specific change. We don’t route around your organization’s AI policy.
If you have a formal AI use policy for third-party vendors, we can review it before engagement and confirm in writing how our tooling aligns. Healthcare, government, and financial services clients should ask about this upfront.
Common questions
Do you copy our data outside of our Cornerstone system?
No. The tooling we built and maintain in house reads from your system in the moment it needs it, and the AI we use reads that same live data. It doesn’t replicate training records, org configurations, or completion histories to external storage.
Does your AI train on our system data?
No. When we use AI tools in your environment, your data is not training input for any external model. We can provide this in writing if procurement requires it.
What happens to our access when the engagement ends?
You deprovision it through your own Cornerstone system controls. We don’t hold credentials, and we confirm in writing that no standing access remains.
Will you sign our NDA or DPA?
Yes, both are standard pre-engagement documents. If you have a vendor-specific template, send it to hello@grovedeck.com and we’ll review it.
Ready to move forward, or still working through procurement? Email hello@grovedeck.com.
Send us your requirementsA Certified Cornerstone Expert, not a sales rep. Earned month to month. No multi-year contract.