4.8/5 of 53 reviews
4.3/5 of 38 reviews

Artificial Intelligence in eSpatial’s Territory Manager


At eSpatial, AI solutions are developed and operated within an information security framework aligned to ISO/IEC 27001, ensuring robust controls for the protection, confidentiality, and integrity of customer data.

People reviewing territory map

Quick answer

This article outlines our security and data privacy practices in relation to AI within the Territory Manager application and reflects our commitment to maintaining transparency as these practices continue to mature.

Data Boundaries & Infrastructure Security


The Territory Manager application in eSpatial employs a structured AI architecture designed to ensure secure, controlled, and auditable interactions between client applications and AI services.

  • Internal Security Perimeter: All message routing, workflow orchestration, and tool execution occur within eSpatial's internal environment. Intermediate data processing remains fully contained within our security perimeter.
  • Controlled Access Gateway: Client interactions enter through a dedicated proxy interface that enforces security policies and acts as a strict barrier between user environments and AI services.
  • Prohibited External Integrations: To maintain tight infrastructure boundaries, third-party or external client connections to internal AI execution tools are currently blocked.

External AI Vendor Safeguards


  • Stateless Response Generation: Natural language processing is handled externally via Anthropic through a commercial agreement. Customer inputs are processed transiently to generate immediate responses and are deleted immediately after completion.
  • Zero Model Training: Customer data is contractually protected and never stored, retained, or utilized by external providers to train, fine-tune, or improve public or third-party AI models. eSpatial does not use customer data to train AI models.

Administrative Governance & Tenant Isolation


  • Disabled by Default: AI features are turned off by default across all customer organizations and require explicit administrative activation.
  • Logical Tenant Isolation: Customer data is strictly segregated within a multi-tenant architecture. If an organization does not activate AI features, no data from that organization is ever transmitted to external AI services.
  • Fine-Grained Permissions: Administrators maintain complete control over which individual users or roles have access to AI capabilities.

Credential Security & Session Management


  • Short-lived Authentication: Interactions generate temporary, time-bound tokens to validate actions internally within the appropriate security context.
  • Token Isolation: External language models never receive, view, or interact with user authentication credentials or security tokens at any stage.

This multi-layered approach guarantees that organizations retain full governance over AI adoption while ensuring sensitive operational and spatial data remains under eSpatial's direct control.

Internal Auditability & Data Retention


  • Self-hosted Monitoring: Activity traces and quality metrics are logged entirely within eSpatial's internal network for operational support and system troubleshooting.
  • Strict 90-day Retention: Log visibility is restricted to authorized personnel via role-based access, and all operational trace logs are automatically deleted after a maximum of 90 days.

You appear to be offline at the moment, this notice will disappear once your device can connect to the internet again