Trusted AI starts with trusted business data
Part of Phocas AI
Our commitment to secure AI in Phocas
AI must follow permission and access controls
AI in Phocas will honor the permissions and data access configured for each user. Adding AI doesn't create a separate route around the access controls already protecting your Phocas data.
Your data is never used to train public AI models
Customer data processed by AI in Phocas is never used to train shared or public AI models, and stays hosted in your region — USA, Canada, UK, EU or Australia.
Built on Phocas security & governance
AI capabilities operate within the security and data governance standards of the wider Phocas platform, rather than being treated as a separate add-on with a different security model. That includes SOC 2 Type II certification, encryption by default and ongoing security testing.
Designed so you can check the result
Customer quote
“Security and compliance have never been optional at Phocas — they’re built in. That hasn’t changed with AI. We’re SOC 2 and GDPR compliant, your data never leaves your environment, it is never used to train any foundation model. When AI is working with your financial and operational data, the trust has to be absolute."
Phocas Trust Layer architecture
One Trust Layer. Applied consistently, everywhere AI shows up in Phocas.
1. Identity & access
Phocas knows who is asking and applies existing permissions and access controls.
2. Business context
Phocas provides the relevant data, definitions and business context from your environment.
3. Secure AI
A suitable AI model performs the task within Phocas security and governance controls.
4. Verifiable output
You get an answer, summary or action you can use, and where supported, a way to check it.
Trusted Phocas data & platform services
A consolidated, structured and governed data foundation with enterprise security, infrastructure and platform services.
Consistent
The same principles apply across every Phocas AI experience.
Connected
Built on the trusted data foundation that powers all Phocas products.
Controlled
Security, permissions and governance remain in place at every step.
Verifiable
Answers are designed to be used with confidence.
The right AI model for the job.
The same security standards.
AI models are improving quickly, and different models are suited to different tasks. Phocas reviews and adopts the right model for each AI experience as technology moves.
Whatever model is behind it, the Phocas Trust Layer stays in place, so switching or upgrading models never means losing the permissions, context or security controls already protecting your data.

AI is only as useful as the context behind it
Generic AI can be remarkably capable. But it doesn’t automatically understand what your products, customers, accounts, branches, margins or other business measures mean. Phocas starts from a different place.
- Connected business data: bring ERP and other business data together in Phocas rather than expecting AI to make sense of disconnected sources
- Shared business context: metrics, dimensions, hierarchies and other structures already used in Phocas help give AI the context it needs to work with your business data
- A foundation for AI across Phocas: the same Analytics data foundation supports Financial Statements, Budgets & Forecasts, Rebates, CRM and Sales Insights

Customer quote
"We've been building for distribution and manufacturing businesses for 25 years. We know the problems, the workflows, we hold the data, we know what a good margin looks like, and where things get complicated. When we apply AI, we're not figuring out the use cases, we already know them. That's why our customers see the benefit quickly."
What happens between your question and the AI's answer
AI experiences in Phocas may differ, but the same trust principles apply around it: who is asking, what they are allowed to access, what business context is required and how the resulting output is handled.
Your Phocas identity and access rights establish what information and functionality are available to you.
The AI experience works within the relevant Phocas permissions so it can use only the business information available to that user.
Where the task requires business data, Phocas can provide the appropriate data, definitions and other context from your environment.
This is what helps turn a general-purpose AI model into an AI experience that can work with your business.
AI performs the required task while the applicable Phocas security and governance controls continue to apply around the experience.
The result might be an answer, summary, recommendation, report, widget or action.
Where supported, Phocas also provides the information needed to help users verify the result before relying on it.
Frequently asked questions
The Phocas Trust Layer is the shared framework of data context, permissions, security and governance principles that supports AI experiences across Phocas.
It explains what sits around the AI model itself – helping determine what information an AI capability can access, what business context it receives and how data and outputs are handled.
Phocas AI is designed to work within the access rights of the person using it. AI does not create a separate permission model or provide a shortcut around existing Phocas data access controls.
No. Customer data used in Phocas AI features is not used to train shared or public AI models.
For questions about your business, Phocas AI uses the data and business context available within Phocas to ground its response.
AI capabilities are built within the wider Phocas security and data governance environment.
That means the same approach to areas such as access control, encryption, platform security, monitoring and independent security assessment continues to apply as AI capabilities are added.
Phocas isn't tied to a single AI model.
We evaluate models and AI services according to the needs of each capability, including quality, reliability, performance, security, data handling and cost.
This allows Phocas to take advantage of improvements in AI technology while maintaining consistent standards around how customer data is handled.
No. The Trust Layer doesn't replace Phocas security, permissions or data governance. It describes how those existing foundations – together with AI-specific controls and business context – support AI experiences across Phocas.
AI-generated outputs can be inaccurate and should be treated appropriately for the task and decision being made.
Phocas designs AI experiences so users remain in control and, where supported, can check the underlying data, calculation or action before relying on the result.
As we add AI to more workflows, the level of human review and verification will depend on what the AI is being asked to do.