CETRAI

AI Agent Platform for Commercial Enterprise

Deploy AI agents across departments: multiple workspaces, role-based access, edit-to-live approval, verified identity lookups, SSO with MFA and a full audit trail.

Multiple agents and workspaces, role-based access scoped per department, and verified identity lookups against your own systems.

What an enterprise deployment includes

One platform across departments: multiple agents and workspaces, role-based access scoped per department, an edit-to-live approval workflow, verified identity lookups with tiered disclosure, single sign-on via Entra ID, Okta, SAML and OIDC with MFA, and a complete audit trail. The same agent runs on the website widget, your phone line and WhatsApp, and implementation is white-glove and pilot-first with written acceptance criteria.

Why enterprise deployments are different

Departments buy separately, security reviews the whole estate, and nothing reaches customers without a review step. The platform is built for that shape of deployment.

  • Multi-agent and multi-workspace
  • Role-based access scoped per department
  • Edit-to-live approval workflow
  • Verified identity lookups
  • Tiered disclosure: public, account-specific, restricted
  • SSO via Entra ID, Okta, SAML and OIDC, with MFA

One agent, every channel

Configure the agent once and deploy it to the channels your customers already use. The same knowledge, guardrails and action permissions apply wherever the conversation happens.

  • Website widget carrying voice and text in one widget
  • Phone line, inbound and outbound
  • WhatsApp conversations, plus WhatsApp alerts to staff
  • Launched from any page on your site

It acts, it does not just answer

The agent verifies identity before it discloses anything account-specific, then works inside your systems during the conversation. Disclosure is tiered — public information, account-specific information, and restricted information are separate levels — and the agent never confirms or denies details as a way around verification.

  • Verified identity lookups
  • Tiered disclosure: public, account-specific, restricted
  • No confirmation-by-denial
  • Record creation, update and search mid-conversation
  • Live booking against real availability
  • Field-scoped reads, permissioned writes, and a full action log

Governed the way regulated buyers ask for

Changes are reviewable, reversible and attributable. Edits move to live through an approval workflow, access is scoped by role and department, and the audit trail is complete.

  • Version history with comparison and one-click restore
  • Edit-to-live approval workflow
  • Role-based access scoped per department
  • Complete audit trail
  • Multi-agent and multi-workspace

Compliance and reliability

The controls procurement asks about, summarised here and documented in full in the trust centre.

  • Cyber Essentials Plus certified
  • SOC 2 Type II examination underway
  • HECVAT Light completed
  • WCAG 2.1 AA, with a VPAT available
  • AES-256 at rest, TLS 1.2+ in transit
  • US, EU and Middle East data residency
  • Single-tenant option
  • Zero-retention mode; no training on client data
  • 99.9% uptime SLA, geo-redundant
  • RPO 4 hours, RTO 8 hours
  • SSO via Entra ID, Okta, SAML and OIDC, with MFA

Ask your deployment a question from Claude or ChatGPT

Staff query their own deployment in the assistant they already use — every conversation that ended badly last week, a specific transcript, what is trending in a department — with no report request and no export. The connection is made over MCP, is workspace-locked, admin-controlled and revocable.

  • Direct queries from Claude and ChatGPT over MCP
  • Workspace-locked, admin-controlled, revocable access
  • REST API
  • Signed webhooks
  • Custom tools pointed at any endpoint

Deployment

Implementation is white-glove and pilot-first, with a named project manager and written acceptance criteria, so the first deployment is scoped and signed off rather than guessed at.

  • White-glove implementation
  • Pilot-first rollout
  • Named project management with written acceptance criteria
  • Staff training and runbooks
  • Enterprise options: white-label, custom widget, enhanced compliance mode, SSO, custom voices, private dataset ingestion

Frequently Asked Questions

What enterprise buyers ask before a deployment is scoped.

  • Does the platform support single sign-on for our staff? Yes. Single sign-on is available via Entra ID, Okta, SAML and OIDC, with MFA. Console access is scoped by role and department, and every change is attributable through the audit trail.
  • Where is our data stored, and is it used for training? Data residency is available in the US, EU and Middle East, with a single-tenant option and a zero-retention mode. Client data is not used for training. Data is encrypted with AES-256 at rest and TLS 1.2+ in transit, and the platform carries a 99.9% uptime SLA on geo-redundant infrastructure.
  • Can separate departments be kept isolated from each other? Yes. The platform is multi-agent and multi-workspace, role-based access is scoped per department, and knowledge bases can be shared or isolated. A logically isolated single-tenant architecture per client is available.
  • What governance controls does the platform include? Version history with comparison and one-click restore, an edit-to-live approval workflow, role-based access scoped per department, a complete audit trail, and multi-agent, multi-workspace separation.
  • Which channels can one agent run on? A website widget carrying voice and text together, your phone line for inbound and outbound calls, and WhatsApp for conversations as well as alerts to staff. The agent is configured once and deployed across those channels, and it can be launched from any page on your site.
  • How do we integrate the agent with our own systems? Through a REST API, signed webhooks, and custom tools pointed at any endpoint. Staff can also query their own deployment from Claude or ChatGPT over MCP, with workspace-locked, admin-controlled and revocable access. Reads are field-scoped, writes are permissioned, and every action is logged.
  • How does the agent handle account-specific information? It verifies identity first, then discloses at the level that identity allows: public information, account-specific information, and restricted information are separate tiers. It does not confirm or deny details as a way around verification. Reads are field-scoped, writes are permissioned, and every action is logged.

Book a demo of an enterprise deployment

Enterprise deployments begin with a demo, then a pilot with a named project manager and written acceptance criteria.