Home / Security

Enterprise security

Enterprise AI, without uncontrolled AI access.

Your data stays protected and every action is governed. Your CIO and CISO can see who can do what, what the AI is allowed to touch, and what happened.

M360 · who sees what
Example campus · illustrative data

The architecture

Five layers between your data and any action.

Enterprise data→Secure data & context→Orchestration→Approved AI services→Validation & governance→Authorized user or system
Data & contextSensitive data is protected and policy controls what context is ever shared.
AccessRole-based permissions and clear boundaries for people and for AI agents.
OrchestrationEach task goes to an approved service with only the context it needs.
ValidationResponses are checked, actions are approved, and everything is logged.
GovernanceHuman oversight, defined automation levels, and alignment with your policies.

How MIS protects enterprise data

The AI never gets a key to your building.

Every request passes through the same governed path. Nothing goes straight from a model to your equipment.

  1. Building dataPoints, alarms, documents and history from your systems
  2. Secure context layerSensitive data protected; policy decides what context can be used
  3. AI orchestrationThe task is routed with only the context it needs
  4. Approved model or serviceOnly services your organization has approved
  5. ValidationAnswers checked; actions checked against limits and roles
  6. Authorized actionCarried out by an approved playbook or a person, and logged

Can the AI write directly to our BAS?

No. Changes go through playbooks that a facilities admin has approved and armed, each with set limits, such as 70–78 °F. Anything outside a playbook goes to a person.

Who approves actions?

People in roles you define. Executives and property managers are read-only by default; facilities admins approve automations and can pause them at any time.

What gets logged?

Every automated action, every approval and every change: what happened, what M360 did, who was told, and when.

What happens if the AI is wrong?

Limits cap what any action can change, rules fall back to safe behavior when an input fails, and findings carry their evidence so your team can check them before acting.

What data leaves our environment, and which AI services see it?

Only what your policy allows, sent only to services your organization has approved. We document the exact data flows and services with your security team before anything is connected.

Where is our data stored?

Hosting, retention and data residency are agreed with your security team as part of the assessment, and written into your deployment documentation.

Roles

Everyone sees what their job needs. Nothing more.

Executive

Outcomes, risk and the bill across the portfolio. Read-only, no equipment controls.

Facilities admin

Equipment, findings with evidence, requests, alert rules, documents and users. Approves automations.

Property manager

Read-only and scoped to one building: status, findings and comfort requests.

Detailed architecture and data-handling documentation is reviewed with your security team during the facility assessment.

See what your buildings could be telling you.