Home / Security
Enterprise security
Enterprise AI, without uncontrolled AI access.
Your data stays protected and every action is governed. Your CIO and CISO can see who can do what, what the AI is allowed to touch, and what happened.
The architecture
Five layers between your data and any action.
How MIS protects enterprise data
The AI never gets a key to your building.
Every request passes through the same governed path. Nothing goes straight from a model to your equipment.
- Building dataPoints, alarms, documents and history from your systems
- Secure context layerSensitive data protected; policy decides what context can be used
- AI orchestrationThe task is routed with only the context it needs
- Approved model or serviceOnly services your organization has approved
- ValidationAnswers checked; actions checked against limits and roles
- Authorized actionCarried out by an approved playbook or a person, and logged
Can the AI write directly to our BAS?
No. Changes go through playbooks that a facilities admin has approved and armed, each with set limits, such as 70–78 °F. Anything outside a playbook goes to a person.
Who approves actions?
People in roles you define. Executives and property managers are read-only by default; facilities admins approve automations and can pause them at any time.
What gets logged?
Every automated action, every approval and every change: what happened, what M360 did, who was told, and when.
What happens if the AI is wrong?
Limits cap what any action can change, rules fall back to safe behavior when an input fails, and findings carry their evidence so your team can check them before acting.
What data leaves our environment, and which AI services see it?
Only what your policy allows, sent only to services your organization has approved. We document the exact data flows and services with your security team before anything is connected.
Where is our data stored?
Hosting, retention and data residency are agreed with your security team as part of the assessment, and written into your deployment documentation.
Roles
Everyone sees what their job needs. Nothing more.
Executive
Outcomes, risk and the bill across the portfolio. Read-only, no equipment controls.
Facilities admin
Equipment, findings with evidence, requests, alert rules, documents and users. Approves automations.
Property manager
Read-only and scoped to one building: status, findings and comfort requests.
Detailed architecture and data-handling documentation is reviewed with your security team during the facility assessment.