Skip to main content

FAQ - Data Protection and Security

Written by Product Management

Is our data being used to train LLMs?

No. TAI utilizes large language models (LLMs) hosted via Amazon Bedrock within the same AWS region as Nezasa's other services. Data sent to Amazon Bedrock is completely isolated and is never shared with third-party AI model providers, nor is it used to train public models.

Does TAI anonymize PII before sending it to the LLM?

No, because anonymization is not required under our architecture. TAI operates entirely within the secure AWS ecosystem where your TripBuilder applications and databases are already hosted.

TAI utilizes AWS Bedrock to access LLMs. Because AWS Bedrock processes data entirely within our secure cloud perimeter, your Personally Identifiable Information (PII) never leaves the protected environment.

How this compares to the legacy Cockpit Copilot: The original TripBuilder Cockpit Copilot (launched in 2025) connected directly to OpenAI, which did require a dedicated PII anonymization layer. In the near future, this legacy version will be completely replaced by a new iteration powered by TAI, inheriting this seamless, perimeter-based AWS security.

What about data protection and security?

TAI is built from the ground up with enterprise-grade security and data privacy. Our core framework includes the following safeguards:

  • Strict Multi-Tenancy: TAI ensures complete data isolation between customers. If you operate multiple brands or business units under one roof, their data remains strictly segregated and invisible to one another.

  • Multi-Provider Support (Future-Proofing): By leveraging Amazon Bedrock, TAI is never locked into a single AI vendor (like OpenAI or Google). Nezasa — or users configuring custom agents — can seamlessly plug in or swap whichever AI performs best for a specific task without any disruption to the client.

  • Zero Vendor Data Access: The foundational AI companies behind the models have absolutely no access to your prompts, the agent's responses, or system logs.

  • No Model Training: Whatever you process through TAI stays yours. Your data is never used to feed back into AI models or improve services for other companies— a critical requirement for compliance teams.

  • PII & GDPR Compliance: Booking data inherently contains passenger information. TAI is engineered to prevent sensitive data leaks into AI training sets or public exposures, ensuring full compliance with GDPR and similar global privacy regulations.

  • Comprehensive Auditing: Every action, request, and system event within TAI is fully logged to ensure total auditability and compliance tracking.

Did this answer your question?