AI trust & safety

AI you can audit

An agent near your money should be transparent, not magical. Here is exactly what CountStand’s AI can see, how it decides, what it will never do, and how every action it takes stays logged and reversible.

The safety model

Six commitments the AI runs under

Human-in-the-loop by default

The agent proposes; you approve anything that matters. Approval is the default, autonomy is opt-in and bounded.

A YES-code on every money move

No spend, payment or transfer happens without your explicit confirmation code. The AI cannot move money on its own.

Governed tools only

The agent can only call the same permissioned, idempotent commands the product uses, never free-form access.

Every action logged and reversible

A full audit log records who, what and when for each AI action, so it can be traced and undone.

Your data stays isolated and encrypted

Row-level security keeps one outlet’s data physically unreadable by another; personal data is AES-256 encrypted.

Not public training data

Your operational data is used to run your restaurant, not to train a public model, and is handled in line with India’s DPDP Act.

What can the AI actually see?

Only your own restaurant’s operational data, and only within strict tenant isolation. CountStand enforces row-level security at the database, so one outlet’s sales, stock and customers are physically unreadable by another, and the agent inherits exactly those boundaries. It sees what a trusted manager of your outlet would see, and nothing beyond it.

Personal data, guest phone numbers and the like, is encrypted (AES-256) and handled in line with India’s DPDP Act, including the right to erasure. The AI works over the operational picture it needs to help you run the place, not a pile of raw personal records.

How does it decide what to propose?

The agent combines a frontier large language model with your live numbers and a set of governed tools. It reads the current state, sales, stock against recipe usage, variance, covers, and reasons about the next useful move: reorder before a stockout, flag a leak that has grown, surface a menu item that has quietly stopped paying.

Where correctness matters, the maths is deterministic, not guessed: GST, money and variance are computed exactly and in integer paise, and the model’s job is to surface, prioritise and explain, not to invent figures. A suggestion always comes with the reason behind it, so you can judge it rather than take it on faith.

What will the AI never do?

It will never move money without your YES-code, spend, pay a supplier or transfer, are gated on an explicit human confirmation every time. It will never reach outside its governed commands to touch your data or systems in an unbounded way, the agent has hands, but only the tools it is permitted to hold. And it will never cross tenant boundaries: another outlet’s data is not visible to it, by construction.

This is the deliberate opposite of a black box. The point of building the AI on the same permissioned, audited command layer as the rest of the product is that its powers are enumerable, and every use of them is recorded.

Can I trust it, and undo it?

Yes, because you can see everything it did. Every AI action is written to an audit log with the actor, the action and the time, and because each action is a governed command, it can be reversed. There is no silent automation: if the agent prepared a purchase order or dismissed an alert, that is on the record and in your control.

The honest summary: the AI is powerful enough to genuinely help and constrained enough to be safe, watching continuously, proposing clearly, acting only through your approval, and leaving a trail you can audit.

See the agent, and its guardrails, on your menu

The best way to judge an AI is to watch it work on your own numbers.